Executive brief
A network router's diagnostic tool allows unauthenticated remote attackers to execute arbitrary system commands through manipulated input parameters. This vulnerability in the Netcore NBR200V2 router enables attackers to take complete control of the device, potentially compromising all traffic and data passing through it. Exploitation is straightforward and public proof-of-concept code is available.
Technical details
A command injection flaw exists in the /www/cgi-bin/network_tools CGI endpoint, triggered via manipulation of the param, key, or val arguments. The vulnerability allows unauthenticated remote code execution on the affected router with no user interaction required. Successful exploitation grants the attacker full system-level access to the device.
Affected products
- Netcore NBR200V2 1.3.241127.071246
Timeline
- 2026-09-21: disclosed: Publicly disclosed; vendor did not respond to early notification
- 2026-09-21: other: Exploit code reported as publicly available