External risk intelligence

Netcore NBR200V2 Command Injection via CGI Diagnostic Endpoint.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-94097

The vulnerability exists in a CGI diagnostic endpoint on a network router/gateway device. Such interfaces are commonly deployed as web-based management portals which are frequently exposed to the network to facilitate remote administration and device monitoring.

Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Netcore NBR200V2 device, specifically within its CGI Diagnostic Endpoint. This flaw allows for remote command injection, meaning an attacker could potentially execute arbitrary commands on the affected device without needing any privileges. The exploit has been publicly disclosed, increasing the risk of its utilization.

  • Remote attackers can inject commands.
  • Confirm if this device is in your environment.
  • Assess potential unauthorized access risks.

Attack Path

How an attacker could exploit the issue

An attacker can remotely exploit this vulnerability without any authentication by sending a specially crafted request to the device's network tools feature. This request manipulates arguments within the CGI diagnostic endpoint, leading to command injection. The vulnerability can then result in a critical compromise of the device.

  • No authentication or user interaction needed.
  • Triggered by manipulating diagnostic tool arguments.
  • Full system compromise is possible.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, remote attackers could execute arbitrary commands on the affected system by manipulating arguments within the CGI Diagnostic Endpoint, potentially impacting service behavior and system data.

  • System commands could be executed.
  • Via crafted network requests.
  • Compromise of the device.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the Netcore NBR200V2 CGI Diagnostic Endpoint requires immediate attention. Given the nature of network routers and their potential exposure, the infrastructure or network security teams are likely responsible for managing this device. The first practical step is to identify all instances of this device within the environment, determine their reachability from external networks, and confirm their business criticality to prioritize remediation efforts.

  • Infrastructure or network security teams should own.
  • Verify device reachability and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Netcore NBR200V2 device?

The Netcore NBR200V2 is a networking device, typically used as a router or gateway to manage internet traffic and connect local devices to a wider network. It includes administrative management portals that allow users to monitor and configure network settings through a web interface.

What does command injection mean for CVE-2026-94097?

This vulnerability involves a weakness class known as command injection (CWE-77). It means the device's diagnostic software incorrectly handles input, allowing an attacker to insert their own commands into a data field. The system then inadvertently runs these malicious commands as if they were legitimate administrative tasks.

How is this vulnerability triggered?

An attacker triggers this bug by sending a specially crafted request to the CGI diagnostic endpoint used for network tools. Simply visiting the device's login page or browsing general traffic does not trigger the vulnerability; it requires specific, intentional manipulation of the parameters used by the diagnostic functions.

Is my Netcore NBR200V2 at risk?

Halo Surface Signal indicates that because this device is a gateway frequently managed via web portals, it is often placed in network-accessible positions. If your device's management interface is reachable from the internet, it is at higher risk of being targeted by remote attackers.

What should I do if I use this device?

Begin by creating an inventory of all NBR200V2 devices in your environment to understand where they are deployed. Prioritize verifying whether these devices are exposed to the internet or other untrusted networks. Once identified, restrict access to the management interface to authorized internal networks only.

References