{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/netcore/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:netcore:nbr200v2_firmware:1.3.241127.071246:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-94095"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NBR200V2 (1.3.241127.071246)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","network-security","vulnerability","cve-2026-94097","command-injection","network-infrastructure"],"_cs_type":"advisory","_cs_vendors":["Netcore"],"content_html":"\u003cp\u003eNetcore NBR200V2 firmware version 1.3.241127.071246 contains a critical command injection vulnerability (CVE-2026-94095) in the Traceroute Diagnostic Feature, located within the /usr/bin/network_tools binary. The vulnerability exists due to insufficient sanitization of the 'url' argument passed to this utility. An unauthenticated, remote attacker can manipulate this input to inject and execute arbitrary shell commands on the affected networking device with the privileges of the network_tools binary. The vulnerability has been publicly disclosed with active exploit potential, and the vendor has provided no response or patch. Given the nature of the device as a networking gateway, successful exploitation provides an attacker with a persistent foothold and potential pivot point into the local network.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated remote code execution, granting full control over the affected NBR200V2 device. In an enterprise or SOHO environment, this allows an attacker to intercept traffic, conduct man-in-the-middle attacks, modify device configuration, or use the device as a staging point for lateral movement. There are no available security patches, representing a high risk for all internet-facing deployments of this product.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eImmediately restrict access to the web management interface and diagnostic features of all Netcore NBR200V2 devices to trusted management subnets only. If remote diagnostic access is not required for standard operations, disable the Traceroute Diagnostic Feature or firewall access to the corresponding API endpoint to prevent remote exploitation of CVE-2026-94095. Given the lack of a vendor patch, consider decommissioning the device or placing it behind a robust WAF/IPS that can identify and block malicious shell metacharacters in the diagnostic feature URL parameters.\u003c/p\u003e\n","date_modified":"2026-09-21T02:25:25Z","date_published":"2026-09-21T00:24:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-netcore-cve-2026-94095/","summary":"Netcore NBR200V2 version 1.3.241127.071246 is vulnerable to remote command injection via the Traceroute Diagnostic Feature, allowing unauthenticated attackers to execute arbitrary commands.","title":"Remote Command Injection in Netcore NBR200V2 Traceroute Feature","url":"https://feed.craftedsignal.io/briefs/2026-09-netcore-cve-2026-94095/"}],"language":"en","title":"CraftedSignal Threat Feed - Netcore","version":"https://jsonfeed.org/version/1.1"}