CVE-2025-5147: Netcore NBR1005GPEV2/NBR200V2/B6V2 network_tools tools_ping command injection
A vulnerability was found in Netcore NBR1005GPEV2, NBR200V2 and B6V2 up to 20250508 and classified as critical. This issue affects the function toolsping of the file /usr/bin/networktools. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5147?
CVE-2025-5147 is classified as a critical vulnerability.
How do I fix CVE-2025-5147?
To fix CVE-2025-5147, update your Netcore NBR1005GPEV2, NBR200V2, or B6V2 device to a version released after May 8, 2025.
What is the impact of CVE-2025-5147?
CVE-2025-5147 allows for command injection through the tools_ping function in the affected devices.
Which devices are affected by CVE-2025-5147?
CVE-2025-5147 affects Netcore NBR1005GPEV2, NBR200V2, and B6V2 devices up to version 20250508.
How can an attacker exploit CVE-2025-5147?
An attacker can exploit CVE-2025-5147 by manipulating the url argument in the tools_ping function.