Sceawere

Vulnerability Detail

CVE-2026-94099UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Netcore NBR200V2 Command Injection Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
2h ago
Vendor
Netcore
Product
NBR200V2
Attack Type
Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-09-21T01:16:29.983Z",
  "pubdate": "2026-09-21T01:16:29.983Z",
  "executiveSummary": "A critical security vulnerability has been identified in the Netcore NBR200V2 router, specifically within the Backup Restore component.\nThe vulnerability is classified as an OS Command Injection flaw triggered via the file restore.cgi.\nThis vulnerability allows a remote, unauthenticated attacker to execute arbitrary system commands with the privileges of the web server process.\nThe root cause involves improper neutralization of special elements used in an OS command within the QUERY_STRING argument.\nGiven that public exploit code is available and the vendor has remained unresponsive to disclosure attempts, the risk of exploitation is significantly elevated.\nSuccessful exploitation grants an attacker full control over the affected device, potentially leading to unauthorized data exfiltration, persistent malware installation, or utilization of the device in a botnet.\nThe vulnerability is remotely exploitable, requiring no prior authentication, which necessitates immediate defensive action by network administrators.",
  "technicalDetails": "The vulnerability resides within the Backup Restore component of the Netcore NBR200V2 firmware, specifically version 1.3.241127.071246.\nThe flaw manifests in the processing logic of the restore.cgi script. The web application fails to properly sanitize or validate the input provided through the QUERY_STRING parameter before passing it to an underlying system shell or sensitive system function.\nAn attacker can manipulate the QUERY_STRING parameter by injecting malicious shell metacharacters such as pipes, semicolons, or backticks to terminate the intended command and append arbitrary system commands. Since the application does not implement robust input filtering or parameterization, these injected commands are executed by the operating system with the permissions associated with the web server daemon.\nThe attack flow proceeds as follows: First, the attacker identifies the entry point in the restore.cgi endpoint. Second, the attacker crafts a malicious HTTP GET request where the QUERY_STRING is weaponized to include OS command sequences. Third, the server parses the request and executes the shell commands before performing the intended backup or restoration logic. Fourth, the output or side effects of the command are executed within the context of the device's firmware environment.\nBecause the service is exposed remotely, no physical access or local network presence is required to initiate the attack. The lack of authentication on the restore.cgi endpoint enables external actors to execute these commands without any valid user credentials.\nThe impact of a successful exploitation is severe. Once command execution is achieved, an attacker can pivot throughout the local network, intercept sensitive traffic, modify system configurations, or deploy persistent backdoors into the firmware. The lack of vendor response means that there is currently no official patch available to address the underlying code flaw, leaving the device in a perpetually vulnerable state unless alternative mitigation strategies are applied."
}
CVE-2026-94099: Netcore NBR200V2 Command Injection Vulnerability (CRITICAL Severity, CVSS: 9.9) | Sceawere