CVE-2026-101001
Received Received - Intake

Command Injection in Netcore NBR200V2 Web Management Interface

Vulnerability report for CVE-2026-101001, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nbr200v2 1.3.241127.071246

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101001 is a command injection vulnerability in the Netcore NBR200V2 router firmware version V1.3.241127.071246. It allows remote attackers to execute arbitrary shell commands with root privileges without authentication. The flaw exists in the /cgi-bin/network_tools endpoint due to a disabled URL decoding function and an eval parsing loop that processes malicious input before authentication checks.

Detection Guidance

To detect this vulnerability, check if your Netcore NBR200V2 router is running firmware version V1.3.241127.071246. Test the /cgi-bin/network_tools endpoint by sending a crafted HTTP GET request with a command injection payload. Use tools like curl to send requests with shell metacharacters and observe if commands execute despite error messages.

Impact Analysis

This vulnerability enables full device compromise. Attackers can steal router configurations, install persistent backdoors, or use the device to move laterally within your network. Exploitation requires crafting a specific HTTP GET request with shell metacharacters, bypassing authentication entirely.

Compliance Impact

This vulnerability allows remote attackers to execute arbitrary commands with root privileges on the Netcore NBR200V2 router. Such unauthorized access could lead to unauthorized data access, modification, or exfiltration, violating GDPR's data protection requirements and HIPAA's security rules for protected health information.

Mitigation Strategies

Immediately update the router firmware to a patched version if available. If no patch exists, restrict access to the web management interface by blocking external connections to /cgi-bin/network_tools. Monitor network traffic for suspicious HTTP GET requests targeting this endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101001. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart