<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>NAP930 (0.1.241010.141410) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/nap930-0.1.241010.141410/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 02:23:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/nap930-0.1.241010.141410/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OS Command Injection in Netcore NAP930 via Network Tools CGI</title><link>https://feed.craftedsignal.io/briefs/2026-09-netcore-cve/</link><pubDate>Tue, 29 Sep 2026 02:23:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-netcore-cve/</guid><description>An unauthenticated remote OS command injection vulnerability in the Netcore NAP930 router allows attackers to execute arbitrary system commands via the sid argument in the network_tools CGI component.</description><content:encoded><![CDATA[<p>A critical OS command injection vulnerability, identified as CVE-2026-102240, affects the Netcore NAP930 router version 0.1.241010.141410. The vulnerability resides within the Network Tools CGI component, specifically in the /www/cgi-bin/network_tools script. The eval function within this script fails to sanitize the sid argument before processing, allowing unauthenticated remote attackers to inject and execute arbitrary operating system commands. This flaw is particularly dangerous as it grants the attacker execution capabilities with high system privileges. The exploit code is publicly available, increasing the risk of exploitation by opportunistic actors. Despite attempts to contact the vendor, no response or patch has been issued, leaving devices vulnerable. Defenders should monitor for unexpected HTTP requests directed at the network_tools CGI endpoint, particularly those containing shell metacharacters in the query string parameters.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows for complete system compromise of the affected Netcore NAP930 router. An attacker can gain persistent unauthorized access, exfiltrate data, or utilize the device as a node in botnet infrastructure. Given the critical CVSS score of 10.0 and public availability of exploit material, there is a high likelihood of automated exploitation attempts across internet-facing devices.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Block all inbound access to the web management interface of Netcore NAP930 routers from untrusted or public networks.</li>
<li>Implement strict access control lists (ACLs) to restrict access to the /www/cgi-bin/network_tools endpoint to known management IP addresses.</li>
<li>Monitor web server logs for incoming requests to /www/cgi-bin/network_tools that include characters such as semicolon, pipe, or backticks in the 'sid' parameter.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>network-device</category></item></channel></rss>