Sceawere
Vulnerability Detail
CVE-2026-94095UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Netcore NBR200V2 Command Injection Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 3h ago
- Vendor
- Netcore
- Product
- NBR200V2
- Attack Type
- Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-09-21T00:16:59.440Z",
"pubdate": "2026-09-21T00:16:59.440Z",
"executiveSummary": "A critical command injection vulnerability exists within the Netcore NBR200V2 router firmware, specifically version 1.3.241127.071246.\nThe vulnerability resides within the Traceroute Diagnostic Feature of the /usr/bin/network_tools utility.\nBy manipulating the 'url' parameter, an unauthenticated remote attacker can inject arbitrary shell commands, leading to full system compromise.\nThe flaw stems from insufficient input sanitization before passing user-supplied data to a system shell or command-line interface.\nGiven the remote exploitability and the fact that public exploit code is available, this vulnerability poses a severe risk to confidentiality, integrity, and availability.\nThe vendor has remained unresponsive to disclosure attempts, leaving affected systems exposed to potential exploitation.",
"technicalDetails": "The vulnerability is classified as an OS command injection flaw located in the /usr/bin/network_tools binary, which powers the Traceroute diagnostic interface on Netcore NBR200V2 devices running version 1.3.241127.071246.\nThe root cause of this security defect is improper neutralization of special elements used in an OS command. The diagnostic functionality takes an 'url' argument from a user-provided request and fails to adequately sanitize this input before incorporating it into a backend system call.\nDuring the attack flow, a remote attacker targets the diagnostic interface. By crafting a malicious payload containing shell metacharacters (such as ';', '&', or '|'), the attacker can terminate the intended traceroute command and append arbitrary system commands that the underlying operating system will execute with the privileges of the network_tools process.\nBecause the component typically executes with administrative or root-level privileges to perform network-level diagnostics, successful exploitation grants the attacker full control over the router's operating environment.\nExploitation does not require prior authentication, meaning any attacker with network access to the device's management interface can execute commands remotely. This significantly increases the attack surface, as the device may be reachable via the WAN interface depending on the router's configuration.\nPost-exploitation impact includes the ability to modify system configuration, exfiltrate sensitive network traffic, deploy persistent malware (such as a reverse shell or botnet agent), or leverage the compromised device as a pivot point for further lateral movement within the local area network.\nThe lack of vendor response indicates that no official patch is currently available, exacerbating the risk to end-users who remain unable to remediate the flaw through standard firmware update procedures."
}