Sceawere

Vulnerability Detail

CVE-2026-101001UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Netcore NBR200V2 OS Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
4h ago
Vendor
Netcore
Product
NBR200V2
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-09-28T05:16:30.570Z",
  "pubdate": "2026-09-28T05:16:30.570Z",
  "executiveSummary": "A critical OS command injection vulnerability exists within the Netcore NBR200V2, specifically within the /www/cgi-bin/network_tools component.\nThe vulnerability is triggered by improper sanitization of the QUERY_STRING argument, which is passed directly to an eval function within the web management interface.\nThis flaw allows a remote, unauthenticated attacker to execute arbitrary system commands on the underlying operating system with the privileges of the web server process.\nThe inability of the device to correctly validate input permits the injection of shell metacharacters, potentially leading to a complete compromise of the affected device.\nGiven the availability of public exploits and the vendor's lack of responsiveness, this vulnerability poses a significant risk to the integrity, confidentiality, and availability of the network infrastructure managed by the affected device.\nThe attack is remotely exploitable, requiring only network connectivity to the web management interface, making it a high-priority risk for organizations utilizing this hardware.",
  "technicalDetails": "The vulnerability resides within the binary or script handling the /www/cgi-bin/network_tools path on the Netcore NBR200V2 web management interface.\nAnalysis of the implementation reveals that the application utilizes the eval function to process input derived from the HTTP QUERY_STRING environment variable without adequate filtering or sanitization.\nIn a secure configuration, input passed to system-level functions or command interpreters must be strictly validated against a whitelist or properly escaped to prevent command concatenation.\nIn this implementation, the QUERY_STRING is concatenated into a command string that is subsequently passed to an execution sink. By crafting a malicious payload containing shell metacharacters such as semicolons (;), pipes (|), or backticks (`), an attacker can escape the intended command structure and execute arbitrary shell instructions.\nThe attack flow proceeds as follows: 1) The attacker identifies the reachable web management interface on the target device. 2) The attacker submits a specially crafted HTTP request where the query string parameters contain injected OS commands. 3) The web management interface extracts the QUERY_STRING and passes it directly to the vulnerable eval function. 4) The server-side process executes the attacker-supplied command within the context of the running web service, which typically runs with elevated privileges. 5) The shell output may be reflected in the HTTP response, providing the attacker with immediate feedback regarding command execution success.\nBecause the eval function executes the string as code or command input, the attacker bypasses standard input validation layers. This vulnerability is particularly severe because it does not require prior authentication, allowing any remote user with network access to the management interface to leverage the exploit.\nThe post-exploitation impact is severe, ranging from arbitrary file read/write, credential exfiltration, and the installation of persistent backdoors, to full device takeover. Once the attacker achieves command execution, they can move laterally through the internal network or utilize the device as a pivot point for further malicious activities. As the vendor has not provided a patch, there is no inherent remediation through firmware updates at this time."
}
CVE-2026-101001: Netcore NBR200V2 OS Command Injection (CRITICAL Severity, CVSS: 10.0) | Sceawere