criticalZero-Day

Netcore NBR200V2 CGI Diagnostic Endpoint Command Injection

First seen Sep 22, 2026 · Updated Sep 22, 2026 · CVSS 10

command-injectionrouter-vulnerabilityCGIunauthenticated-RCEIoTnetwork-devicepublic-exploit

A critical unauthenticated command injection vulnerability exists in the Netcore NBR200V2 router's CGI diagnostic endpoint (/www/cgi-bin/network_tools), allowing remote attackers to execute arbitrary commands via the param/key/val arguments. The vendor has not responded to disclosure and no patch is currently available, while a public exploit exists, making this an immediate high-risk threat to exposed devices.

Technical Analysis

CVE-2026-94097 affects the CGI Diagnostic Endpoint of Netcore NBR200V2 firmware version 1.3.241127.071246, where improper sanitization of the param, key, and val arguments passed to the network_tools script enables OS command injection. Attackers can remotely execute arbitrary shell commands on the router without authentication, likely leading to full device compromise, persistent backdoor installation, or use as a pivot point into internal networks. The CVSS score of 10.0 reflects the low attack complexity, lack of required privileges, and full impact on confidentiality, integrity, and availability. Given the vendor's lack of response, no official patch is expected in the near term, increasing the window of exposure for internet-facing or improperly segmented devices. Organizations running AI agents or edge inference workloads behind or on networks using this router model face risk of network-level compromise, credential interception, or lateral movement toward agent orchestration hosts and API endpoints, making this agent-relevant for any deployment reliant on router-level network trust boundaries.

Affected Systems

Netcore NBR200V2 router, firmware version 1.3.241127.071246 (and potentially earlier/related firmware sharing the same CGI codebase)

Indicators of Compromise

  • Endpoint: /www/cgi-bin/network_tools
  • Affected parameters: param, key, val
  • No specific hashes, IPs, or malware samples reported at this time

Remediation Steps

  1. 1

    Isolate affected devices

    Remove NBR200V2 routers from direct internet exposure; restrict CGI diagnostic endpoint access to trusted internal management networks only.

  2. 2

    Disable diagnostic tools

    If configurable, disable the network_tools CGI diagnostic feature until a vendor patch is released.

  3. 3

    Deploy network segmentation

    Segment IoT/router management interfaces from critical infrastructure, including hosts running AI agents, RAG pipelines, or LLM tool-use services, to limit lateral movement.

  4. 4

    Monitor for exploitation

    Deploy IDS/IPS signatures to detect command injection attempts against the /www/cgi-bin/network_tools endpoint.

  5. 5

    Track vendor advisories

    Continuously monitor Netcore and NVD for a forthcoming patch, given the vendor's current non-response to disclosure.

  6. 6

    Consider device replacement

    If no patch is issued within a reasonable timeframe, evaluate replacing affected routers with actively supported alternatives.

CVE / Advisory IDs

CVE-2026-94097

Industries Most Exposed

TelecommunicationsConsumer ElectronicsSmall Business/SOHO NetworkingCritical Infrastructure (via exposed edge devices)Managed Service Providers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.