Sceawere

Vulnerability Detail

CVE-2026-102240UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Netcore NAP930 OS Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
5h ago
Vendor
Netcore
Product
NAP930
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-09-29T02:16:55.153Z",
  "pubdate": "2026-09-29T02:16:55.153Z",
  "executiveSummary": "A critical OS command injection vulnerability exists within the Network Tools CGI component of the Netcore NAP930 router, specifically within the /www/cgi-bin/network_tools file.\nThe vulnerability originates from improper neutralization of user-supplied input provided via the 'sid' argument, which is processed by the 'eval' function.\nSuccessful exploitation allows an unauthenticated remote attacker to execute arbitrary system commands with the privileges of the web server process.\nThis vulnerability presents a severe risk as it permits full system compromise, unauthorized data access, and potential persistence mechanisms.\nGiven that the exploit is publicly available and the vendor has remained unresponsive, the attack surface is significantly exposed to malicious actors capable of network-level interaction with the device.\nImmediate remediation is constrained by the lack of official vendor patches, necessitating defensive network-level isolation.",
  "technicalDetails": "The vulnerability resides in the Network Tools CGI component, specifically located at /www/cgi-bin/network_tools on the Netcore NAP930 device (version 0.1.241010.141410).\nThe root cause is identified as an unsafe call to the 'eval' function within the CGI binary. The application fails to perform adequate input validation or sanitization on the 'sid' argument before passing the data to the shell or an evaluation context.\nThe attack flow begins when a remote attacker sends a specially crafted HTTP request to the /www/cgi-bin/network_tools endpoint. By injecting shell metacharacters (such as backticks, semicolons, or pipes) into the 'sid' parameter, the attacker can break out of the intended logic of the 'eval' function.\nOnce the input is parsed by the 'eval' function, the underlying shell interprets the injected sequences as legitimate operating system commands. This effectively transforms a benign management query into a command execution primitive.\nBecause the 'eval' function processes the malicious payload directly, the attacker can execute arbitrary commands with the user ID assigned to the web service (typically 'root' or a high-privilege service account on embedded networking devices).\nExploitation does not require prior authentication, and the vulnerability is reachable from remote network locations, significantly increasing the attack vector's scope.\nPost-exploitation impact includes, but is not limited to, the modification of system configurations, exfiltration of sensitive information, installation of backdoors for persistent access, and the potential inclusion of the device into a botnet.\nThe absence of vendor intervention means that the underlying logic error remains unpatched, providing a stable platform for automated exploitation scripts that have been made public. Attackers can leverage this to gain full control over the router's operating system, potentially leading to interception or manipulation of network traffic traversing the device."
}
CVE-2026-102240: Netcore NAP930 OS Command Injection (CRITICAL Severity, CVSS: 10.0) | Sceawere