Skip to content
Threat Feed
critical advisory

Remote Command Injection in Netcore NBR200V2 Traceroute Feature

Netcore NBR200V2 version 1.3.241127.071246 is vulnerable to remote command injection via the Traceroute Diagnostic Feature, allowing unauthenticated attackers to execute arbitrary commands.

CVE search metadata

CVE search record: CVE-2026-94095. Severity: critical. CVSS: 9.9. KEV: no. Product: NBR200V2 (1.3.241127.071246). Brief: Remote Command Injection in Netcore NBR200V2 Traceroute Feature. Brief link: https://feed.craftedsignal.io/briefs/2026-09-netcore-cve-2026-94095/

What's new

  • 1. added detection rule: Detects CVE-2026-94097 Exploitation - Command Injection via CGI Endpoint Sep 21, 00:24 via nvd

Netcore NBR200V2 firmware version 1.3.241127.071246 contains a critical command injection vulnerability (CVE-2026-94095) in the Traceroute Diagnostic Feature, located within the /usr/bin/network_tools binary. The vulnerability exists due to insufficient sanitization of the 'url' argument passed to this utility. An unauthenticated, remote attacker can manipulate this input to inject and execute arbitrary shell commands on the affected networking device with the privileges of the network_tools binary. The vulnerability has been publicly disclosed with active exploit potential, and the vendor has provided no response or patch. Given the nature of the device as a networking gateway, successful exploitation provides an attacker with a persistent foothold and potential pivot point into the local network.

Impact

The vulnerability allows unauthenticated remote code execution, granting full control over the affected NBR200V2 device. In an enterprise or SOHO environment, this allows an attacker to intercept traffic, conduct man-in-the-middle attacks, modify device configuration, or use the device as a staging point for lateral movement. There are no available security patches, representing a high risk for all internet-facing deployments of this product.

Recommendation

Immediately restrict access to the web management interface and diagnostic features of all Netcore NBR200V2 devices to trusted management subnets only. If remote diagnostic access is not required for standard operations, disable the Traceroute Diagnostic Feature or firewall access to the corresponding API endpoint to prevent remote exploitation of CVE-2026-94095. Given the lack of a vendor patch, consider decommissioning the device or placing it behind a robust WAF/IPS that can identify and block malicious shell metacharacters in the diagnostic feature URL parameters.


Immediate actions

Restrict access to the management web interface of Netcore NBR200V2 devices.

IT Operations 24h

Mitigations

Disable the Traceroute Diagnostic Feature if possible or block access to the URL argument functionality at the firewall.

immediate IT Operations

CVE-2026-94095

Detection coverage 1

Detects CVE-2026-94097 Exploitation - Command Injection via CGI Endpoint

critical

Detects exploitation attempts against Netcore routers where shell metacharacters are passed to the network_tools CGI diagnostic endpoint.

sigma tactics: execution, initial_access techniques: T1059 sources: webserver

Detection queries are available on the platform. Get full rules →