Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2972+ Articles
168+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. Security
  3. CVE-2026-94099: Command Injection in Netcore NBR200V2 Backup Restore Endpoint
CVE-2026-94099: Command Injection in Netcore NBR200V2 Backup Restore Endpoint

Critical Security Alert

This vulnerability is actively being exploited. Immediate action is recommended.

SECURITYCRITICALCVE-2026-94099

CVE-2026-94099: Command Injection in Netcore NBR200V2 Backup Restore Endpoint

The restore.cgi backup-restore endpoint on Netcore NBR200V2 routers is vulnerable to unauthenticated command injection via QUERY_STRING.

Dylan H.

Security Team

September 21, 2026
3 min read

Affected Products

  • Netcore NBR200V2 1.3.241127.071246

Overview

A fifth command injection vulnerability has been disclosed in the Netcore NBR200V2 router, firmware version 1.3.241127.071246, in the Backup Restore component at restore.cgi. Tracked as CVE-2026-94099, the flaw lets a remote, unauthenticated attacker inject shell commands via the QUERY_STRING argument processed when a configuration backup is restored.

This is part of a six-vulnerability cluster disclosed together in this firmware — see Related Reading for the full set.


Technical Details

FieldValue
CVE IDCVE-2026-94099
SeverityCritical (CVSS 3.1: 9.9)
WeaknessCWE-77 (Command Injection)
Vulnerable Filerestore.cgi
ComponentBackup Restore
ParameterQUERY_STRING
AuthenticationNone required
Exploit MaturityPublic PoC available
Vendor ResponseContacted early, did not respond

How It Works

restore.cgi reads the request's QUERY_STRING while processing a configuration-restore operation and passes it into a shell command without sanitization. Because restore operations typically run with privileges sufficient to rewrite system configuration, an attacker who injects shell metacharacters into the query string can execute arbitrary commands in that same privileged context — no valid backup file or authentication required to trigger the underlying command execution.


Impact Assessment

Who Is At Risk

  • Any NBR200V2 unit on firmware 1.3.241127.071246 with the web management interface reachable — backup/restore functionality is frequently left enabled even on otherwise locked-down configurations
  • No vendor patch exists

Potential Impact

  • Arbitrary command execution with the privileges required to rewrite router configuration
  • Configuration tampering risk — an attacker in this code path could also manipulate the legitimate restore mechanism to push a malicious configuration in addition to direct command execution
  • Full device and downstream network compromise, consistent with the rest of the cluster

Mitigation

  • Block external access to restore.cgi; disable WAN-facing management entirely if possible
  • Deploy WAF/IPS signatures for shell metacharacters in query strings targeting the restore path
  • Audit backup/restore logs for unexpected restore operations
  • No vendor patch exists; plan for hardware replacement if continued use is required

References

  • VulDB — CVE-2026-94099

Related Reading

  • CVE-2026-94095: Netcore NBR200V2 Traceroute Command Injection Enables Root RCE
  • CVE-2026-94096: Command Injection in Netcore NBR200V2 LAN IP Configuration Handler
  • CVE-2026-94097: Netcore NBR200V2 CGI Diagnostic Endpoint Command Injection
  • CVE-2026-94098: Command Injection in Netcore NBR200V2 Firmware Upgrade Endpoint
  • CVE-2026-94100: Buffer Overflow in Netcore NBR200V2 WAN VLAN Reconfiguration
#Netcore#CVE-2026-94099#Command Injection#Router Security#IoT Security#RCE

Related Articles

CVE-2026-94098: Command Injection in Netcore NBR200V2 Firmware Upgrade Endpoint

Netcore NBR200V2's firmware upgrade CGI endpoint injects the QUERY_STRING argument into a shell command, enabling unauthenticated remote injection.

3 min read

CVE-2026-94097: Netcore NBR200V2 CGI Diagnostic Endpoint Command Injection

A third command injection flaw in Netcore NBR200V2's network_tools CGI endpoint lets remote attackers run arbitrary shell commands unauthenticated.

3 min read

CVE-2026-94096: Command Injection in Netcore NBR200V2 LAN IP Configuration Handler

Netcore NBR200V2 routers are vulnerable to unauthenticated command injection via the ipv4 argument in the LAN IP configuration handler.

3 min read
Back to all Security Alerts