Cyber & AI intelligence
Wasteland.
Briefs indexed2926
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-102240 2026-09-29

Netcore NAP930 Network Tools CGI Flaw Enables Unauthenticated Remote OS Command Injection (CVE-2026-102240)

"CVE-2026-102240 is a critical OS command injection vulnerability in the Network Tools CGI of Netcore NAP930 firmware 0.1.241010.141410. A public exploit exists and the vendor has not responded to the disclosure."

CVE-2026-102240 is a critical OS command injection vulnerability in the Network Tools CGI of Netcore NAP930 firmware 0.1.241010.141410. A public exploit exists and the vendor has not responded to the disclosure.

What Is It

The flaw is in the eval function of /www/cgi-bin/network_tools, part of the device's Network Tools CGI component. An attacker who manipulates the sid argument can inject operating system commands. The CNA, VulDB, classifies the weakness as CWE-77 (Command Injection) and CWE-78 (OS Command Injection).

According to the NVD record, the attack can be launched remotely. VulDB published the CVE on 2026-09-29, and NVD lists its status as "Received."

Why It Matters

VulDB rates this as critical or maximum severity on every CVSS version it scored. CVSS 3.1 and CVSS 2.0 are at the maximum of 10.0, and CVSS 4.0 is 9.3:

The vectors describe a network-reachable attack with low complexity. It needs no privileges and no user interaction. Confidentiality, integrity and availability impacts are all high, and the CVSS 3.1 score has a changed scope.

The description says the exploit "has been made public and could be used." A public write-up is linked in the references.

KEV status: CVE-2026-102240 is not in the CISA Known Exploited Vulnerabilities catalog. The supplied data contains no confirmed in-the-wild exploitation.

What's Vulnerable

No other affected versions are listed in the supplied data.

Patch Status

The NVD record lists no patch, fixed version or vendor advisory. The disclosure says Netcore was contacted early but "did not respond in any way." Because the CVE is not in KEV, there is no CISA-mandated required action or due date.

Sources