PatchSiren

Netcore CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Netcore CVE published 2026-09-21

CVE-2026-94101

A buffer overflow vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246, specifically in the vlan_load_form_uci function of /usr/bin/routerd. The vulnerability can be exploited remotely by manipulating the wan_num argument. The exploit has been publicly disclosed, and although the vendor was contacted, no response was received. The vulnerability has a CVSS score of 8.6 and is considered HI [truncated]

HIGH Netcore CVE published 2026-09-21

CVE-2026-94100

A buffer overflow vulnerability has been identified in Netcore NBR200V2 1.3.241127.071246, specifically in the wan_config_set_vlan function of the /usr/bin/routerd component. This weakness is related to the manipulation of the vlan_wanX.ports argument and can be exploited remotely. The exploit has been made public, potentially enabling attacks. However, the vendor has not responded to this disclosure.

HIGH Netcore CVE published 2026-09-21

CVE-2026-94099

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is possible to be carried out remotely. The vulnerability has been publicly disclosed and may be used for attacks. The vendor was contact [truncated]

HIGH Netcore CVE published 2026-09-21

CVE-2026-94098

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246, affecting the firmware upgrade CGI endpoint. This vulnerability allows for command injection via manipulation of the QUERY_STRING argument and can be executed remotely. The exploit is publicly available. Defenders should assess exposure and prioritize patching or mitigation. IT and security teams managing network infrastructure should v [truncated]

CRITICAL Netcore CVE published 2026-09-21

CVE-2026-94097

A critical vulnerability was found in Netcore NBR200V2 1.3.241127.071246, affecting the CGI Diagnostic Endpoint. This issue allows for command injection via manipulation of the 'param', 'key', or 'val' arguments. Remote exploitation is possible, and a public exploit has been disclosed. The vendor, Unknown Vendor, was notified but did not respond. The vulnerability has significant implications for network [truncated]

HIGH Netcore CVE published 2026-09-21

CVE-2026-94096

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246, affecting the LAN IP Configuration Handler's /usr/bin/network_tools file. The vulnerability is caused by a command injection issue triggered by manipulating the ipv4 argument, allowing an attacker to inject malicious commands. This could lead to unauthorized access or disruption of service. Defenders should verify the affected version and ap [truncated]

HIGH Netcore CVE published 2026-09-21

CVE-2026-94095

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246, affecting an unknown functionality of the file /usr/bin/network_tools in the Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection, which can be initiated remotely. The exploit has been disclosed publicly. The vendor was contacted but did not respond.