Junglewise Threat Intelligence

CVE-2026-94097: Netcore NBR200V2 command injection in network tools CGI

CVE-2026-94097 · Severity: critical · CVSS 10 · Published 2026-09-21

Vendors: Netcore.

Executive brief

A network router's diagnostic tool allows unauthenticated remote attackers to execute arbitrary system commands through manipulated input parameters. This vulnerability in the Netcore NBR200V2 router enables attackers to take complete control of the device, potentially compromising all traffic and data passing through it. Exploitation is straightforward and public proof-of-concept code is available.

Technical details

A command injection flaw exists in the /www/cgi-bin/network_tools CGI endpoint, triggered via manipulation of the param, key, or val arguments. The vulnerability allows unauthenticated remote code execution on the affected router with no user interaction required. Successful exploitation grants the attacker full system-level access to the device.

Affected products

  • Netcore NBR200V2 1.3.241127.071246

Timeline

  • 2026-09-21: disclosed: Publicly disclosed; vendor did not respond to early notification
  • 2026-09-21: other: Exploit code reported as publicly available

References

Related threats