Cyber & AI intelligence
Wasteland.
Briefs indexed2779
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-94099 2026-09-20

Netcore NBR200V2 Command Injection (CVE-2026-94099): Public Exploit, No Vendor Response

"A command injection flaw in the Backup Restore component of the Netcore NBR200V2 router carries a CVSS 3.1 score of 9.9 (CRITICAL), has a publicly released exploit, and has drawn no response from the vendor."

A command injection flaw in the Backup Restore component of the Netcore NBR200V2 router carries a CVSS 3.1 score of 9.9 (CRITICAL), has a publicly released exploit, and has drawn no response from the vendor.

What Is It

CVE-2026-94099 is a command injection vulnerability (CWE-74, CWE-77) in Netcore NBR200V2 firmware version 1.3.241127.071246. The flaw sits in unspecified processing of the file restore.cgi, part of the Backup Restore component. Manipulating the QUERY_STRING argument results in command injection. The attack can be carried out remotely.

The CVE was published by VulDB ([email protected]) and is currently in "Received" status in NVD.

Why It Matters

The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, base score 9.9, CRITICAL. Network-reachable, low attack complexity, no user interaction, and only low privileges required. The scope is marked as Changed, with High confidentiality, integrity, and availability impact on both the vulnerable component and downstream components. The CVSS 4.0 secondary score is 8.6 (HIGH) with exploit maturity rated PROOF_OF_CONCEPT.

Per the advisory, the exploit has been released to the public and may be used for attacks. That moves this from theoretical to opportunistically exploitable.

No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the wild in the available source data.

What's Vulnerable

Patch Status

No fix is identified in the supplied data. The advisory states the vendor was contacted early about this disclosure but did not respond in any way. There is no vendor patch, mitigation, or required-action guidance in the source record, and no KEV remediation deadline. Operators running the affected firmware should treat the device's management interface as untrusted and restrict network reachability accordingly.

Sources