๐Ÿ” CVE Alert

CVE-2026-94098

CRITICAL 9.1

Netcore NBR200V2 Firmware Upgrade CGI Endpoint upgrade command injection

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-77 CWE-74
Vendor netcore
Product nbr200v2
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for netcore nbr200v2

Be the first to know when new critical vulnerabilities affecting netcore nbr200v2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Netcore / NBR200V2
1.3.241127.071246

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/408027 vuldb.com: https://vuldb.com/vuln/408027/cti vuldb.com: https://vuldb.com/cve/CVE-2026-94098 vuldb.com: https://vuldb.com/submit/892991 app.notion.com: https://app.notion.com/p/Netcore-NBR200V2-Vul-6-39f797159f1580259aa3cc1d0f512fde

Credits

๐Ÿ” FirmHarness (VulDB User) VulDB CNA Team