Sceawere
Vulnerability Detail
CVE-2026-101002UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Netcore NBR200V2 Command Injection Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 3h ago
- Vendor
- Netcore
- Product
- NBR200V2
- Attack Type
- OS Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-09-28T06:16:29.783Z",
"pubdate": "2026-09-28T06:16:29.783Z",
"executiveSummary": "A critical OS command injection vulnerability has been identified in the Netcore NBR200V2 router, specifically within the firmware version 1.3.241127.071246.\nThe vulnerability resides in the Tools Ping Handler component, which improperly sanitizes user-supplied input before passing it to the underlying operating system.\nSuccessful exploitation allows a remote, unauthenticated attacker to execute arbitrary system commands with the privileges of the network_tools process.\nThis vulnerability poses a high risk to the confidentiality, integrity, and availability of the affected device, potentially leading to full system compromise.\nThe exploit for this vulnerability is currently public, and the vendor has not provided a response or a patch, necessitating immediate manual mitigation by network administrators.",
"technicalDetails": "The vulnerability is localized within the function system located in the binary /usr/bin/network_tools of the Netcore NBR200V2 router. The flaw is triggered via the URL argument passed to the Ping Handler diagnostic utility.\nRoot Cause: The root cause of this vulnerability is the improper validation and sanitization of input provided to the URL argument. The application fails to sanitize metacharacters, such as shell operators (e.g., ;, |, &&, `), that can be used to break out of the intended Ping command execution context and execute secondary, malicious OS commands.\nAttack Flow: An attacker can remotely trigger this vulnerability by sending a specially crafted HTTP request targeting the Ping Handler utility. By injecting shell metacharacters into the 'url' parameter, the attacker forces the system shell to interpret the injected sequence as a command, executing it with the existing privileges of the /usr/bin/network_tools binary.\nExploitation Method: Since the application invokes a system-level command (typically ping) using the attacker-supplied parameter, the command is executed within a shell environment. If the input string is not effectively escaped, the operating system treats the trailing injected arguments as new instructions.\nPayload Behavior: An attacker may utilize common payloads such as reverse shells, binary downloads from external servers, or command execution to exfiltrate configuration data or modify device settings. Because the vulnerability is remotely accessible and public exploits exist, the barrier to entry for potential attackers is extremely low.\nPost-Exploitation Impact: Successful exploitation results in remote code execution (RCE). The attacker effectively gains control over the affected device's underlying Linux operating system. This allows for persistent access through the installation of backdoors, pivoting into the internal network, or rendering the device unusable. Given that these devices often operate at the network edge, compromise can facilitate Man-in-the-Middle (MitM) attacks against all internal traffic routed through the NBR200V2 unit."
}