CVE-2026-101001 | Netcore NBR200V2 1.3.241127.071246 Web Management Interface network_tools eval QUERY_STRING os command injection
A vulnerability described as very critical has been identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection.
This vulnerability is referenced as CVE-2026-101001. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More