CVE-2026-101002
Received Received - Intake

Command Injection in Netcore NBR200V2

Vulnerability report for CVE-2026-101002, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nbr200v2 1.3.241127.071246

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101002 is a command injection vulnerability in the Netcore NBR200V2 router firmware version V1.3.241127.071246. It exists in the network_tools.tools_ping ubus method where user input in the url parameter is passed unsanitized into a system() call in the /usr/bin/network_tools service. This allows authenticated attackers to execute arbitrary commands with root privileges.

Detection Guidance

To detect CVE-2026-101002, check if your Netcore NBR200V2 router runs firmware version V1.3.241127.071246. Verify if the vulnerable /usr/bin/network_tools binary exists and inspect for unauthenticated command injection in the tools_ping or tools_traceroute methods. Test by sending crafted URL parameters with payloads like ';id' to observe command execution.

Impact Analysis

An attacker with valid web session credentials can exploit this to gain full device compromise, including executing arbitrary commands with root privileges. This could lead to complete control over the router, data theft, or use as a pivot point for further network attacks. The vulnerability can also be chained with other unauthenticated issues in the same firmware.

Compliance Impact

This vulnerability could lead to unauthorized access and control of network devices, potentially exposing sensitive data. For GDPR, it may result in data breaches requiring notification under Article 33. For HIPAA, it risks compromising protected health information if the device is used in healthcare environments.

Mitigation Strategies

Immediately update the router firmware to a patched version if available. Disable remote access to the web interface if not required. Change default credentials to strong passwords and disable any known default accounts. Block external access to ubus ports (typically 1000) via firewall rules. Monitor network traffic for suspicious activity targeting the router's web interface or ubus methods.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101002. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart