{"id":"CVE-2026-94098","published":"2026-09-21T01:16:29.800","lastModified":"2026-09-21T17:19:19.577","description":"A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-74","CWE-77"],"vendors":[],"products":[],"references":[{"url":"https://app.notion.com/p/Netcore-NBR200V2-Vul-6-39f797159f1580259aa3cc1d0f512fde","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-94098","tags":[]},{"url":"https://vuldb.com/submit/892991","tags":[]},{"url":"https://vuldb.com/vuln/408027","tags":[]},{"url":"https://vuldb.com/vuln/408027/cti","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The vulnerability allows for command injection via the QUERY_STRING argument in the Firmware Upgrade CGI Endpoint, enabling remote execution of arbitrary commands.","exploitability":"Exploitation is relatively straightforward given the remote execution capability and the manipulation of the QUERY_STRING argument.","blast_radius":"If exploited, this vulnerability could lead to complete compromise of the device, including data theft, denial of service, and further lateral movement.","remediation":"Upgrade to Netcore NBR200V2 1.3.241127.071246 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","cgi","command-injection"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:05:56.578Z"}}