A command injection flaw in the Backup Restore component of the Netcore NBR200V2 router carries a CVSS 3.1 score of 9.9 (CRITICAL), has a publicly released exploit, and has drawn no response from the vendor.
What Is It
CVE-2026-94099 is a command injection vulnerability (CWE-74, CWE-77) in Netcore NBR200V2 firmware version 1.3.241127.071246. The flaw sits in unspecified processing of the file restore.cgi, part of the Backup Restore component. Manipulating the QUERY_STRING argument results in command injection. The attack can be carried out remotely.
The CVE was published by VulDB ([email protected]) and is currently in "Received" status in NVD.
Why It Matters
The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, base score 9.9, CRITICAL. Network-reachable, low attack complexity, no user interaction, and only low privileges required. The scope is marked as Changed, with High confidentiality, integrity, and availability impact on both the vulnerable component and downstream components. The CVSS 4.0 secondary score is 8.6 (HIGH) with exploit maturity rated PROOF_OF_CONCEPT.
Per the advisory, the exploit has been released to the public and may be used for attacks. That moves this from theoretical to opportunistically exploitable.
No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the wild in the available source data.
What's Vulnerable
- Vendor: Netcore
- Product: NBR200V2
- Affected version: 1.3.241127.071246
- Component: Backup Restore (
restore.cgi) - CPE:
cpe:2.3:a:netcore:nbr200v2:*:*:*:*:*:*:*:*
Patch Status
No fix is identified in the supplied data. The advisory states the vendor was contacted early about this disclosure but did not respond in any way. There is no vendor patch, mitigation, or required-action guidance in the source record, and no KEV remediation deadline. Operators running the affected firmware should treat the device's management interface as untrusted and restrict network reachability accordingly.
Sources
- NVD, CVE-2026-94099: https://nvd.nist.gov/vuln/detail/CVE-2026-94099
- VulDB, CVE-2026-94099: https://vuldb.com/cve/CVE-2026-94099
- VulDB, Vulnerability 408028: https://vuldb.com/vuln/408028
- VulDB, CTI data for 408028: https://vuldb.com/vuln/408028/cti
- VulDB, Submission 892992: https://vuldb.com/submit/892992
- Researcher writeup (Notion): https://app.notion.com/p/Netcore-NBR200V2-Vul-7-39f797159f158028ab02c136450d87e4