Junglewise Threat Intelligence

CVE-2026-94095: Netcore NBR200V2 command injection in traceroute diagnostic

CVE-2026-94095 · Severity: critical · CVSS 9.9 · Published 2026-09-21

Technologies: Netcore NBR200V2. Vendors: Netcore.

Executive brief

Netcore NBR200V2 is a network router used to manage corporate and home network traffic. A command injection vulnerability in its traceroute diagnostic feature allows remote attackers to execute arbitrary commands on the device by manipulating the URL parameter, potentially leading to complete device compromise and network access for malicious purposes.

Technical details

A command injection vulnerability exists in the /usr/bin/network_tools utility within the traceroute diagnostic feature of Netcore NBR200V2. The vulnerability is triggered via the url argument and allows unauthenticated remote code execution. An attacker can inject shell commands into the url parameter to execute arbitrary commands on the affected device.

Affected products

  • Netcore NBR200V2 1.3.241127.071246

Timeline

  • 2026-09-21: disclosed: Vulnerability disclosed publicly

References

Related threats