Executive brief
Netcore NBR200V2 is a network backup and restore appliance used for data protection. An attacker can remotely inject arbitrary commands through the restore.cgi file by manipulating the QUERY_STRING parameter, allowing complete system compromise without authentication. Public exploits are already available.
Technical details
The vulnerability is a remote command injection flaw in the Backup Restore component's restore.cgi file. An attacker can craft malicious QUERY_STRING parameters to execute arbitrary system commands, and the attack requires no authentication or user interaction. The vendor was contacted but provided no response or patch.
Affected products
- Netcore NBR200V2 1.3.241127.071246
Timeline
- 2026-09-21: disclosed: Public disclosure with available exploit code
- 2026-09-21: other: Vendor contacted but did not respond