Overview
CVE-2026-101001 is a critical OS command injection vulnerability in the Netcore NBR200V2 router, firmware version 1.3.241127.071246. The flaw lives in the Web Management Interface's /www/cgi-bin/network_tools script, specifically in its eval function, which passes the QUERY_STRING argument through to a shell command without sanitization. Tracked under CWE-78 (OS Command Injection, secondary CWE-77), the bug carries a maximum CVSS score of 10.0 (Critical) — network-exploitable, no authentication, no user interaction, full impact to confidentiality, integrity, and availability.
This is one of a related pair of command-injection flaws disclosed against the NBR200V2's network_tools CGI endpoint alongside CVE-2026-101002; see Related Reading.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-101001 |
| Severity | Critical (CVSS: 10.0) |
| Weakness | CWE-78 (OS Command Injection) / CWE-77 |
| Vulnerable File | /www/cgi-bin/network_tools |
| Function | eval |
| Component | Web Management Interface |
| Parameter | QUERY_STRING |
| Authentication | None required |
| MITRE ATT&CK | T1202 (Indirect Command Execution) |
| Exploit Maturity | Public PoC available |
| Vendor Response | Contacted early, did not respond |
How It Works
The network_tools CGI script on the NBR200V2's web management interface builds a shell command using the raw QUERY_STRING value and passes it to eval without neutralizing shell metacharacters. Because the script runs as part of the web management backend, an attacker who submits a crafted QUERY_STRING to the endpoint can inject arbitrary shell commands that execute with the CGI process's privileges — no login, session token, or prior foothold required. Public proof-of-concept code documenting the exact injection payload has been published, and estimated exploit value on gray-market pricing trackers sits in the $0–$5,000 range, consistent with a trivially weaponizable, unauthenticated bug.
Impact Assessment
Who Is At Risk
- Any NBR200V2 unit on firmware 1.3.241127.071246 with the web management interface reachable over the network
- No vendor patch exists
Potential Impact
- Full remote code execution on the device via the web management CGI process
- Given the "diagnostic tool" nature of
network_tools, a successful attack likely runs with elevated privileges sufficient to reconfigure, exfiltrate from, or fully take over the router - Combined with the related CVE-2026-101002 (same script, different handler) and CVE-2026-101000 (missing authorization on
uci.apply), the NBR200V2/NBR100V2 firmware family has multiple independent, unauthenticated paths to compromise
Mitigation
- Restrict access to the web management interface to trusted management hosts only; disable WAN-side/remote administration
- Deploy network-layer monitoring for anomalous requests to
/www/cgi-bin/network_tools, particularlyQUERY_STRINGvalues containing shell metacharacters (;,|,`,$() - No vendor patch exists; organizations should treat NBR200V2 hardware on this firmware version as unsuitable for continued production use