Netcore NBR200V2 CGI Diagnostic Endpoint Command Injection
First seen Sep 22, 2026 · Updated Sep 22, 2026 · CVSS 10
A critical unauthenticated command injection vulnerability exists in the Netcore NBR200V2 router's CGI diagnostic endpoint (/www/cgi-bin/network_tools), allowing remote attackers to execute arbitrary commands via the param/key/val arguments. The vendor has not responded to disclosure and no patch is currently available, while a public exploit exists, making this an immediate high-risk threat to exposed devices.
Technical Analysis
CVE-2026-94097 affects the CGI Diagnostic Endpoint of Netcore NBR200V2 firmware version 1.3.241127.071246, where improper sanitization of the param, key, and val arguments passed to the network_tools script enables OS command injection. Attackers can remotely execute arbitrary shell commands on the router without authentication, likely leading to full device compromise, persistent backdoor installation, or use as a pivot point into internal networks. The CVSS score of 10.0 reflects the low attack complexity, lack of required privileges, and full impact on confidentiality, integrity, and availability. Given the vendor's lack of response, no official patch is expected in the near term, increasing the window of exposure for internet-facing or improperly segmented devices. Organizations running AI agents or edge inference workloads behind or on networks using this router model face risk of network-level compromise, credential interception, or lateral movement toward agent orchestration hosts and API endpoints, making this agent-relevant for any deployment reliant on router-level network trust boundaries.
Affected Systems
Netcore NBR200V2 router, firmware version 1.3.241127.071246 (and potentially earlier/related firmware sharing the same CGI codebase)
Indicators of Compromise
- Endpoint: /www/cgi-bin/network_tools
- Affected parameters: param, key, val
- No specific hashes, IPs, or malware samples reported at this time
Remediation Steps
- 1
Isolate affected devices
Remove NBR200V2 routers from direct internet exposure; restrict CGI diagnostic endpoint access to trusted internal management networks only.
- 2
Disable diagnostic tools
If configurable, disable the network_tools CGI diagnostic feature until a vendor patch is released.
- 3
Deploy network segmentation
Segment IoT/router management interfaces from critical infrastructure, including hosts running AI agents, RAG pipelines, or LLM tool-use services, to limit lateral movement.
- 4
Monitor for exploitation
Deploy IDS/IPS signatures to detect command injection attempts against the /www/cgi-bin/network_tools endpoint.
- 5
Track vendor advisories
Continuously monitor Netcore and NVD for a forthcoming patch, given the vendor's current non-response to disclosure.
- 6
Consider device replacement
If no patch is issued within a reasonable timeframe, evaluate replacing affected routers with actively supported alternatives.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.