Cyber & AI intelligence
Wasteland.
Briefs indexed2779
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-94096 2026-09-20

CVE-2026-94096: Command Injection in Netcore NBR200V2 Routers

"A public proof-of-concept exists for a critical command injection flaw in the Netcore NBR200V2 router's LAN IP configuration handler, and the vendor has not responded to disclosure."

A public proof-of-concept exists for a critical command injection flaw in the Netcore NBR200V2 router's LAN IP configuration handler, and the vendor has not responded to disclosure.

What Is It

CVE-2026-94096 is a command injection vulnerability (CWE-77, CWE-74) in Netcore NBR200V2 firmware version 1.3.241127.071246. The flaw is in the LAN IP Configuration Handler component, in the file /usr/bin/network_tools. Manipulating the ipv4 argument results in command injection. The attack can be launched remotely.

NVD carries a CVSS 3.1 base score of 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, low privileges required, no user interaction, and a scope change with high confidentiality, integrity, and availability impact. A separate CVSS 4.0 assessment scores the same issue 8.6 (HIGH) and flags exploit maturity as PROOF_OF_CONCEPT; the two scores come from different scoring systems and are not in conflict.

Why It Matters

A proof-of-concept exploit is publicly available. Command injection on a router's network configuration path means an attacker who reaches the management interface with low privileges can execute arbitrary commands on the device. The CVSS 3.1 scope-change rating reflects that the impact extends beyond the vulnerable component itself; consistent with a network edge device that mediates traffic for everything behind it.

There is no CISA KEV entry for this CVE, so active exploitation in the wild is not confirmed by KEV at this time. The public PoC still lowers the bar considerably.

What's Vulnerable

Patch Status

No patch or fixed version is identified in the supplied data. Per the NVD record, the vendor was contacted early about this disclosure but did not respond in any way. No vendor advisory or remediation guidance is available in the source material, and no CISA KEV required action applies. The CVE record status is "Received," meaning it has been submitted to NVD but has not yet completed analysis.

Sources