{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anetcorenap930/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:netcore:nap930:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-102240"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NAP930 (0.1.241010.141410)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","network-device"],"_cs_type":"advisory","_cs_vendors":["Netcore"],"content_html":"\u003cp\u003eA critical OS command injection vulnerability, identified as CVE-2026-102240, affects the Netcore NAP930 router version 0.1.241010.141410. The vulnerability resides within the Network Tools CGI component, specifically in the /www/cgi-bin/network_tools script. The eval function within this script fails to sanitize the sid argument before processing, allowing unauthenticated remote attackers to inject and execute arbitrary operating system commands. This flaw is particularly dangerous as it grants the attacker execution capabilities with high system privileges. The exploit code is publicly available, increasing the risk of exploitation by opportunistic actors. Despite attempts to contact the vendor, no response or patch has been issued, leaving devices vulnerable. Defenders should monitor for unexpected HTTP requests directed at the network_tools CGI endpoint, particularly those containing shell metacharacters in the query string parameters.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows for complete system compromise of the affected Netcore NAP930 router. An attacker can gain persistent unauthorized access, exfiltrate data, or utilize the device as a node in botnet infrastructure. Given the critical CVSS score of 10.0 and public availability of exploit material, there is a high likelihood of automated exploitation attempts across internet-facing devices.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBlock all inbound access to the web management interface of Netcore NAP930 routers from untrusted or public networks.\u003c/li\u003e\n\u003cli\u003eImplement strict access control lists (ACLs) to restrict access to the /www/cgi-bin/network_tools endpoint to known management IP addresses.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for incoming requests to /www/cgi-bin/network_tools that include characters such as semicolon, pipe, or backticks in the 'sid' parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T02:23:52Z","date_published":"2026-09-29T02:23:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-netcore-cve/","summary":"An unauthenticated remote OS command injection vulnerability in the Netcore NAP930 router allows attackers to execute arbitrary system commands via the sid argument in the network_tools CGI component.","title":"OS Command Injection in Netcore NAP930 via Network Tools CGI","url":"https://feed.craftedsignal.io/briefs/2026-09-netcore-cve/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:netcore:nap930:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}