All CosmicBytez Labs articles tagged #Netcore, across news, security advisories, how-to guides, and projects.
An unauthenticated command injection in Netcore NBR200V2's traceroute tool lets attackers run arbitrary commands as root via ubus JSON-RPC.
Netcore NBR200V2 routers are vulnerable to unauthenticated command injection via the ipv4 argument in the LAN IP configuration handler.
A third command injection flaw in Netcore NBR200V2's network_tools CGI endpoint lets remote attackers run arbitrary shell commands unauthenticated.
Netcore NBR200V2's firmware upgrade CGI endpoint injects the QUERY_STRING argument into a shell command, enabling unauthenticated remote injection.
The restore.cgi backup-restore endpoint on Netcore NBR200V2 routers is vulnerable to unauthenticated command injection via QUERY_STRING.
A buffer overflow in Netcore NBR200V2's routerd WAN VLAN handler can be triggered remotely via the vlan_wanX.ports argument.