<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Netcore - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/netcore/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 21 Sep 2026 00:24:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/netcore/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection in Netcore NBR200V2 Traceroute Feature</title><link>https://feed.craftedsignal.io/briefs/2026-09-netcore-cve-2026-94095/</link><pubDate>Mon, 21 Sep 2026 00:24:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-netcore-cve-2026-94095/</guid><description>Netcore NBR200V2 version 1.3.241127.071246 is vulnerable to remote command injection via the Traceroute Diagnostic Feature, allowing unauthenticated attackers to execute arbitrary commands.</description><content:encoded><![CDATA[<p>Netcore NBR200V2 firmware version 1.3.241127.071246 contains a critical command injection vulnerability (CVE-2026-94095) in the Traceroute Diagnostic Feature, located within the /usr/bin/network_tools binary. The vulnerability exists due to insufficient sanitization of the 'url' argument passed to this utility. An unauthenticated, remote attacker can manipulate this input to inject and execute arbitrary shell commands on the affected networking device with the privileges of the network_tools binary. The vulnerability has been publicly disclosed with active exploit potential, and the vendor has provided no response or patch. Given the nature of the device as a networking gateway, successful exploitation provides an attacker with a persistent foothold and potential pivot point into the local network.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthenticated remote code execution, granting full control over the affected NBR200V2 device. In an enterprise or SOHO environment, this allows an attacker to intercept traffic, conduct man-in-the-middle attacks, modify device configuration, or use the device as a staging point for lateral movement. There are no available security patches, representing a high risk for all internet-facing deployments of this product.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Immediately restrict access to the web management interface and diagnostic features of all Netcore NBR200V2 devices to trusted management subnets only. If remote diagnostic access is not required for standard operations, disable the Traceroute Diagnostic Feature or firewall access to the corresponding API endpoint to prevent remote exploitation of CVE-2026-94095. Given the lack of a vendor patch, consider decommissioning the device or placing it behind a robust WAF/IPS that can identify and block malicious shell metacharacters in the diagnostic feature URL parameters.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>network-security</category><category>vulnerability</category><category>cve-2026-94097</category><category>command-injection</category><category>network-infrastructure</category></item></channel></rss>