CVE-2026-94097 | Netcore NBR200V2 1.3.241127.071246 CGI Diagnostic Endpoint network_tools param/key/val command injection

SecurityVulns

A vulnerability identified as very critical has been detected in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection.

This vulnerability is registered as CVE-2026-94097. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More