Remote Command Injection in Netcore NBR200V2 Traceroute Feature
Netcore NBR200V2 version 1.3.241127.071246 is vulnerable to remote command injection via the Traceroute Diagnostic Feature, allowing unauthenticated attackers to execute arbitrary commands.
CVE search metadata
CVE search record: CVE-2026-94095. Severity: critical. CVSS: 9.9. KEV: no. Product: NBR200V2 (1.3.241127.071246). Brief: Remote Command Injection in Netcore NBR200V2 Traceroute Feature. Brief link: https://feed.craftedsignal.io/briefs/2026-09-netcore-cve-2026-94095/
What's new
- 1. added detection rule: Detects CVE-2026-94097 Exploitation - Command Injection via CGI Endpoint Sep 21, 00:24 via nvd
Netcore NBR200V2 firmware version 1.3.241127.071246 contains a critical command injection vulnerability (CVE-2026-94095) in the Traceroute Diagnostic Feature, located within the /usr/bin/network_tools binary. The vulnerability exists due to insufficient sanitization of the 'url' argument passed to this utility. An unauthenticated, remote attacker can manipulate this input to inject and execute arbitrary shell commands on the affected networking device with the privileges of the network_tools binary. The vulnerability has been publicly disclosed with active exploit potential, and the vendor has provided no response or patch. Given the nature of the device as a networking gateway, successful exploitation provides an attacker with a persistent foothold and potential pivot point into the local network.
Impact
The vulnerability allows unauthenticated remote code execution, granting full control over the affected NBR200V2 device. In an enterprise or SOHO environment, this allows an attacker to intercept traffic, conduct man-in-the-middle attacks, modify device configuration, or use the device as a staging point for lateral movement. There are no available security patches, representing a high risk for all internet-facing deployments of this product.
Recommendation
Immediately restrict access to the web management interface and diagnostic features of all Netcore NBR200V2 devices to trusted management subnets only. If remote diagnostic access is not required for standard operations, disable the Traceroute Diagnostic Feature or firewall access to the corresponding API endpoint to prevent remote exploitation of CVE-2026-94095. Given the lack of a vendor patch, consider decommissioning the device or placing it behind a robust WAF/IPS that can identify and block malicious shell metacharacters in the diagnostic feature URL parameters.
Immediate actions
Restrict access to the management web interface of Netcore NBR200V2 devices.
Mitigations
Disable the Traceroute Diagnostic Feature if possible or block access to the URL argument functionality at the firewall.
CVE-2026-94095
Detection coverage 1
Detects CVE-2026-94097 Exploitation - Command Injection via CGI Endpoint
criticalDetects exploitation attempts against Netcore routers where shell metacharacters are passed to the network_tools CGI diagnostic endpoint.
Detection queries are available on the platform. Get full rules →