CVE-2026-94095: Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/networktools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability can be exploited remotely, but the supplied severity vector indicates that the attacker needs low-level privileges. No user interaction is required.
Is exploit code available?
Yes. The exploit has been publicly disclosed and may be used by attackers.
What component should be prioritized for investigation?
Prioritize the Traceroute Diagnostic Feature and its handling of the url argument in /usr/bin/network_tools. Manipulation of that argument is reported to result in command injection.
Is a vendor fix or response available?
The available information does not identify a fix. The vendor was contacted before disclosure but did not respond.