CVE-2026-102240 is a critical OS command injection vulnerability in the Network Tools CGI of Netcore NAP930 firmware 0.1.241010.141410. A public exploit exists and the vendor has not responded to the disclosure.
What Is It
The flaw is in the eval function of /www/cgi-bin/network_tools, part of the device's Network Tools CGI component. An attacker who manipulates the sid argument can inject operating system commands. The CNA, VulDB, classifies the weakness as CWE-77 (Command Injection) and CWE-78 (OS Command Injection).
According to the NVD record, the attack can be launched remotely. VulDB published the CVE on 2026-09-29, and NVD lists its status as "Received."
Why It Matters
VulDB rates this as critical or maximum severity on every CVSS version it scored. CVSS 3.1 and CVSS 2.0 are at the maximum of 10.0, and CVSS 4.0 is 9.3:
- CVSS 3.1: 10.0 CRITICAL (
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) - CVSS 4.0: 9.3 CRITICAL, with exploit maturity set to Proof-of-Concept
- CVSS 2.0: 10.0
The vectors describe a network-reachable attack with low complexity. It needs no privileges and no user interaction. Confidentiality, integrity and availability impacts are all high, and the CVSS 3.1 score has a changed scope.
The description says the exploit "has been made public and could be used." A public write-up is linked in the references.
KEV status: CVE-2026-102240 is not in the CISA Known Exploited Vulnerabilities catalog. The supplied data contains no confirmed in-the-wild exploitation.
What's Vulnerable
- Vendor: Netcore
- Product: NAP930
- Affected version: 0.1.241010.141410
- Component: Network Tools CGI (
/www/cgi-bin/network_tools) - CPE:
cpe:2.3:a:netcore:nap930:*:*:*:*:*:*:*:*
No other affected versions are listed in the supplied data.
Patch Status
The NVD record lists no patch, fixed version or vendor advisory. The disclosure says Netcore was contacted early but "did not respond in any way." Because the CVE is not in KEV, there is no CISA-mandated required action or due date.