Executive brief
Netcore NBR200V2 is a network device that manages LAN IP configuration. An attacker can inject arbitrary commands through the IPv4 parameter in the network_tools utility, gaining remote code execution with critical impact. The vulnerability is publicly exploited and the vendor has not responded to disclosure.
Technical details
A command injection vulnerability exists in /usr/bin/network_tools, the LAN IP Configuration Handler component, where the ipv4 argument is not properly sanitized before being passed to system commands. The vulnerability allows unauthenticated remote code execution over the network. Exploitation enables an attacker to execute arbitrary commands with the privileges of the network_tools process.
Affected products
- Netcore NBR200V2 1.3.241127.071246
Timeline
- 2026-09-21: disclosed
- 2026-09-21: exploited: exploit made public