Netcore · Nbr200V2 · CVE-2026-94097
**Name of the Vulnerable Software and Affected Versions**
Netcore NBR200V2 version 1.3.241127.071246
**Description**
Command injection is possible in the CGI Diagnostic Endpoint component via the `/www/cgi-bin/network tools` endpoint. The issue occurs when the component processes the `param/key/val` argument, allowing externally supplied diagnostic input to influence command execution. This flaw can be exploited remotely without authentication or user interaction.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict management reachability to designated administrative hosts and remove unnecessary public exposure.
Review remote-maintenance and VPN access paths as well as WAN rules to minimize the risk of exploitation.