SECURITYCRITICALCVE-2026-101001

CVE-2026-101001: Netcore NBR200V2 Web Management Interface OS Command Injection via network_tools

Unauthenticated OS command injection in Netcore NBR200V2's network_tools CGI handler via QUERY_STRING gives remote attackers root-level code execution.

Dylan H.

Security Team

September 28, 2026
3 min read
CVE-2026-101001: Netcore NBR200V2 Web Management Interface OS Command Injection via network_tools

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Netcore NBR200V2 1.3.241127.071246

Overview

CVE-2026-101001 is a critical OS command injection vulnerability in the Netcore NBR200V2 router, firmware version 1.3.241127.071246. The flaw lives in the Web Management Interface's /www/cgi-bin/network_tools script, specifically in its eval function, which passes the QUERY_STRING argument through to a shell command without sanitization. Tracked under CWE-78 (OS Command Injection, secondary CWE-77), the bug carries a maximum CVSS score of 10.0 (Critical) — network-exploitable, no authentication, no user interaction, full impact to confidentiality, integrity, and availability.

This is one of a related pair of command-injection flaws disclosed against the NBR200V2's network_tools CGI endpoint alongside CVE-2026-101002; see Related Reading.


Technical Details

FieldValue
CVE IDCVE-2026-101001
SeverityCritical (CVSS: 10.0)
WeaknessCWE-78 (OS Command Injection) / CWE-77
Vulnerable File/www/cgi-bin/network_tools
Functioneval
ComponentWeb Management Interface
ParameterQUERY_STRING
AuthenticationNone required
MITRE ATT&CKT1202 (Indirect Command Execution)
Exploit MaturityPublic PoC available
Vendor ResponseContacted early, did not respond

How It Works

The network_tools CGI script on the NBR200V2's web management interface builds a shell command using the raw QUERY_STRING value and passes it to eval without neutralizing shell metacharacters. Because the script runs as part of the web management backend, an attacker who submits a crafted QUERY_STRING to the endpoint can inject arbitrary shell commands that execute with the CGI process's privileges — no login, session token, or prior foothold required. Public proof-of-concept code documenting the exact injection payload has been published, and estimated exploit value on gray-market pricing trackers sits in the $0–$5,000 range, consistent with a trivially weaponizable, unauthenticated bug.


Impact Assessment

Who Is At Risk

  • Any NBR200V2 unit on firmware 1.3.241127.071246 with the web management interface reachable over the network
  • No vendor patch exists

Potential Impact

  • Full remote code execution on the device via the web management CGI process
  • Given the "diagnostic tool" nature of network_tools, a successful attack likely runs with elevated privileges sufficient to reconfigure, exfiltrate from, or fully take over the router
  • Combined with the related CVE-2026-101002 (same script, different handler) and CVE-2026-101000 (missing authorization on uci.apply), the NBR200V2/NBR100V2 firmware family has multiple independent, unauthenticated paths to compromise

Mitigation

  • Restrict access to the web management interface to trusted management hosts only; disable WAN-side/remote administration
  • Deploy network-layer monitoring for anomalous requests to /www/cgi-bin/network_tools, particularly QUERY_STRING values containing shell metacharacters (;, |, `, $()
  • No vendor patch exists; organizations should treat NBR200V2 hardware on this firmware version as unsuitable for continued production use

References