Overview
A critical command injection vulnerability has been disclosed in the Netcore NBR200V2 router, firmware version 1.3.241127.071246. Tracked as CVE-2026-94095, the flaw sits in the Traceroute Diagnostic Feature of /usr/bin/network_tools, where the url argument is passed to the traceroute handler through the device's ubus JSON-RPC interface and concatenated directly into a shell command without sanitization.
This is the first of six related vulnerabilities disclosed together in this firmware build (CVE-2026-94095 through CVE-2026-94100) — see Related Reading below for the full cluster. A public proof-of-concept, including a working exploit chain from ubus call to root system() execution, is already available on GitHub.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-94095 |
| Severity | Critical (CVSS 3.1: 9.9) |
| Weakness | CWE-77 (Command Injection) |
| Vulnerable File | /usr/bin/network_tools |
| Component | Traceroute Diagnostic Feature |
| Parameter | url |
| Authentication | None required |
| Exploit Maturity | Public PoC available (GitHub) |
| Vendor Response | Contacted early, did not respond |
How It Works
The traceroute handler in network_tools accepts an attacker-controlled url value delivered over the router's ubus JSON-RPC bus and builds a shell command string that embeds it directly — no escaping, no allow-list, no shell-metacharacter filtering. A url value containing command separators (;, |, `, $()) breaks out of the intended traceroute invocation and executes attacker-supplied commands with whatever privileges the network_tools process holds, which on this firmware is root.
Impact Assessment
Who Is At Risk
- Any NBR200V2 unit running firmware 1.3.241127.071246 with the diagnostic/
ubusinterface reachable, whether directly on the WAN or through an exposed management plane - Netcore did not respond to disclosure attempts, so no vendor patch is currently available — every deployed unit on this firmware is exposed indefinitely absent a workaround
Potential Impact
- Full root compromise of the router's underlying Linux environment via a single unauthenticated request
- Network-wide pivot — as with any router-level RCE, a compromised device gives an attacker a foothold to intercept, redirect, or inspect all traffic passing through it
- Botnet recruitment — a working public exploit against an unpatched, unauthenticated router RCE is exactly the kind of vulnerability mass-scanning botnets weaponize quickly
Mitigation
- Disable remote/WAN access to the diagnostic and
ubusinterfaces immediately; there is no vendor patch to apply - Restrict management-plane access to trusted internal hosts only via network ACLs
- Deploy IPS/WAF signatures that flag shell metacharacters in
url-style diagnostic parameters - Monitor for anomalous process spawns originating from
/usr/bin/network_tools - Given the vendor's non-response, organizations relying on NBR200V2 hardware should evaluate replacement options rather than waiting on an official fix
References
Related Reading
- CVE-2026-94096: Command Injection in Netcore NBR200V2 LAN IP Configuration Handler
- CVE-2026-94097: Netcore NBR200V2 CGI Diagnostic Endpoint Command Injection
- CVE-2026-94098: Command Injection in Netcore NBR200V2 Firmware Upgrade Endpoint
- CVE-2026-94099: Command Injection in Netcore NBR200V2 Backup Restore Endpoint
- CVE-2026-94100: Buffer Overflow in Netcore NBR200V2 WAN VLAN Reconfiguration