Junglewise Threat Intelligence

CVE-2026-94099: Netcore NBR200V2 command injection in restore.cgi

CVE-2026-94099 · Severity: critical · CVSS 9.9 · Published 2026-09-21

Technologies: Netcore NBR200V2. Vendors: Netcore.

Executive brief

Netcore NBR200V2 is a network backup and restore appliance used for data protection. An attacker can remotely inject arbitrary commands through the restore.cgi file by manipulating the QUERY_STRING parameter, allowing complete system compromise without authentication. Public exploits are already available.

Technical details

The vulnerability is a remote command injection flaw in the Backup Restore component's restore.cgi file. An attacker can craft malicious QUERY_STRING parameters to execute arbitrary system commands, and the attack requires no authentication or user interaction. The vendor was contacted but provided no response or patch.

Affected products

  • Netcore NBR200V2 1.3.241127.071246

Timeline

  • 2026-09-21: disclosed: Public disclosure with available exploit code
  • 2026-09-21: other: Vendor contacted but did not respond

References

Related threats