Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-94095: Netcore NBR200V2 traceroute feature allows remote code execution
CVE-2026-94095 · published 5 days ago
Summary
The traceroute diagnostic tool on Netcore NBR200V2 can be tricked into running any command by sending a specially crafted URL. An attacker on the network could use this to take control of the device. Apply any available vendor patch, or disable the traceroute feature until a fix is released.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| netcore | nbr200v2 | 1.3.241127.071246 |
Original advisory text
Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
8.6
High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS 3%
Type
CWE-77Command Injection
CWE-74Injection
Timeline
Published21 Sep 2026
Updated25 Sep 2026
First seen20 Sep 2026
Track software like this
Free during beta