{"id":"CVE-2026-94095","published":"2026-09-21T00:16:59.440","lastModified":"2026-09-21T20:17:40.513","description":"A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvssScore":9.9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-74","CWE-77"],"vendors":[],"products":[],"references":[{"url":"https://app.notion.com/p/Netcore-NBR200V2-Vul-3-39f797159f15802296c7f6e110363435","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-94095","tags":[]},{"url":"https://vuldb.com/submit/892986","tags":[]},{"url":"https://vuldb.com/vuln/408024","tags":[]},{"url":"https://vuldb.com/vuln/408024/cti","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"A command injection vulnerability exists in the Traceroute Diagnostic Feature of Netcore NBR200V2 1.3.241127.071246, allowing remote attackers to execute arbitrary commands via the manipulation of the 'url' argument.","exploitability":"Exploitation is relatively straightforward given the remote initiation and command injection nature of the vulnerability.","blast_radius":"If exploited, this could lead to complete compromise of the device and potential lateral movement within the network.","remediation":"Upgrade to the latest version of Netcore NBR200V2, specifically version 1.3.241127.071246 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","command-injection","remote-exploit","network-device"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:57:00.110Z"}}