CVE-2026-102240
Received Received - Intake

Command Injection in Netcore NAP930 Firmware

Vulnerability report for CVE-2026-102240, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nap930 0.1.241010.141410

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated OS command injection vulnerability in the Netcore NAP930 WiFi 6 Access Point running firmware version V0.1.241010.141410. The flaw exists in the network_tools CGI script which improperly handles user input by executing raw, unvalidated commands with root privileges. An attacker on the local network can exploit this by sending a crafted HTTP GET request to /cgi-bin/network_tools, injecting arbitrary shell commands via the 'sid' parameter.

Detection Guidance

To detect this vulnerability, check if your Netcore NAP930 device is running firmware version V0.1.241010.141410. Use network scanning tools like nmap to identify devices with open ports 80 or 443. Send a crafted HTTP GET request to /cgi-bin/network_tools with a test parameter to see if command injection is possible. Example: curl -v 'http://<device-ip>/cgi-bin/network_tools?sid=1;id'

Verify if the device has a default empty root password or if telnetd is running. Check logs for unusual commands or access attempts. Use tcpdump to monitor traffic to the device for suspicious activity.

Impact Analysis

Exploitation enables full device compromise, including configuration theft, persistent backdoors, and network pivoting. The issue is further exacerbated by the device's default empty root password and always-running telnetd service. Proof-of-concept demonstrates command execution, file writes, and even reverse shell access.

Compliance Impact

This vulnerability allows unauthenticated remote attackers to execute arbitrary OS commands with root privileges on the Netcore NAP930 device. Such unauthorized access could lead to unauthorized data access, modification, or exfiltration, violating GDPR's data protection requirements and HIPAA's security rules for protected health information.

Mitigation Strategies

Immediately isolate the affected device from your network to prevent exploitation. Disable telnetd if enabled and change the default root password to a strong one. Update the firmware to the latest version if a patch is available. Block external access to the device's web interface.

Monitor network traffic for signs of compromise. Consider replacing the device if no patch is released, as the vulnerability allows full device takeover and network pivoting.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102240. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart