Executive brief
Netcore NBR200V2 is a network router used to manage corporate connectivity. An attacker can remotely inject arbitrary system commands through the firmware upgrade interface, allowing them to execute code with full device privileges. This could lead to network compromise, data theft, or device takeover.
Technical details
A command injection vulnerability exists in the /www/cgi-bin/upgrade firmware upgrade CGI endpoint, where the QUERY_STRING parameter is not properly sanitized before being passed to system calls. An unauthenticated remote attacker can exploit this flaw over the network to execute arbitrary commands on the device. The vulnerability is publicly exploitable and the vendor has not provided a patch.
Affected products
- Netcore NBR200V2 1.3.241127.071246
Timeline
- 2026-09-21: disclosed: Public disclosure of CVE-2026-94098