Sceawere
Vulnerability Detail
CVE-2026-102240UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Netcore NAP930 OS Command Injection
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 5h ago
- Vendor
- Netcore
- Product
- NAP930
- Attack Type
- OS Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-09-29T02:16:55.153Z",
"pubdate": "2026-09-29T02:16:55.153Z",
"executiveSummary": "A critical OS command injection vulnerability exists within the Network Tools CGI component of the Netcore NAP930 router, specifically within the /www/cgi-bin/network_tools file.\nThe vulnerability originates from improper neutralization of user-supplied input provided via the 'sid' argument, which is processed by the 'eval' function.\nSuccessful exploitation allows an unauthenticated remote attacker to execute arbitrary system commands with the privileges of the web server process.\nThis vulnerability presents a severe risk as it permits full system compromise, unauthorized data access, and potential persistence mechanisms.\nGiven that the exploit is publicly available and the vendor has remained unresponsive, the attack surface is significantly exposed to malicious actors capable of network-level interaction with the device.\nImmediate remediation is constrained by the lack of official vendor patches, necessitating defensive network-level isolation.",
"technicalDetails": "The vulnerability resides in the Network Tools CGI component, specifically located at /www/cgi-bin/network_tools on the Netcore NAP930 device (version 0.1.241010.141410).\nThe root cause is identified as an unsafe call to the 'eval' function within the CGI binary. The application fails to perform adequate input validation or sanitization on the 'sid' argument before passing the data to the shell or an evaluation context.\nThe attack flow begins when a remote attacker sends a specially crafted HTTP request to the /www/cgi-bin/network_tools endpoint. By injecting shell metacharacters (such as backticks, semicolons, or pipes) into the 'sid' parameter, the attacker can break out of the intended logic of the 'eval' function.\nOnce the input is parsed by the 'eval' function, the underlying shell interprets the injected sequences as legitimate operating system commands. This effectively transforms a benign management query into a command execution primitive.\nBecause the 'eval' function processes the malicious payload directly, the attacker can execute arbitrary commands with the user ID assigned to the web service (typically 'root' or a high-privilege service account on embedded networking devices).\nExploitation does not require prior authentication, and the vulnerability is reachable from remote network locations, significantly increasing the attack vector's scope.\nPost-exploitation impact includes, but is not limited to, the modification of system configurations, exfiltration of sensitive information, installation of backdoors for persistent access, and the potential inclusion of the device into a botnet.\nThe absence of vendor intervention means that the underlying logic error remains unpatched, providing a stable platform for automated exploitation scripts that have been made public. Attackers can leverage this to gain full control over the router's operating system, potentially leading to interception or manipulation of network traffic traversing the device."
}