Summary
CVE-2026-101001 is a critical, unauthenticated OS command injection vulnerability in the Web Management Interface of the Netcore NBR200V2 router, firmware version 1.3.241127.071246. The flaw resides in the network_tools CGI script and allows a remote, unauthenticated attacker to execute arbitrary operating system commands with root privileges. Public exploit code is available, and the vendor has not responded to disclosure, so the vulnerability is currently unpatched.
Technical details
- Root cause: the
network_toolsCGI script (/www/cgi-bin/network_tools) contains aurldecode()sanitization routine whose call is commented out, so the rawQUERY_STRINGvalue is passed directly into anevalstatement. - The vulnerable
evalcall executes before the script’s authentication check, so no valid session or credentials are required to reach it. - Attack vector: a crafted HTTP GET request to
/cgi-bin/network_toolswith a shell metacharacter payload injected into a query-string parameter (e.g.,a=';id>/www/x.txt;:'), with spaces substituted using${IFS}since the request cannot contain literal&characters. - Impact: full remote code execution as root on the device, enabling configuration exfiltration, persistent backdoor installation, and use of the router as a pivot point into the internal network.
Affected software
- Netcore NBR200V2 router firmware version 1.3.241127.071246
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No vendor patch is currently available; Netcore was contacted about this disclosure prior to publication but did not respond.
- Network mitigations: Remove any direct internet exposure of the router’s web management interface; restrict access to the management interface to trusted internal networks only, and place affected devices behind a firewall or VPN that blocks unauthenticated inbound access to the CGI management endpoints.
- Monitor for unexpected outbound connections or unfamiliar processes/files on affected devices, as public exploit code exists for this vulnerability.
- Track vendor communications for a firmware update and apply it as soon as one is released.

