在 Netcore NBR200V2 1.3.241127.071246 中识别出一项漏洞。该漏洞影响 Web 管理界面组件中 /www/cgi-bin/network_tools 文件的 eval 函数。通过操纵 QUERY_STRING 参数,可导致操作系统命令注入。该攻击可远程执行。相关利用代码已公开,存在被滥用的风险。厂商在披露初期即被联系,但至今未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101000 | 10.0 CRITICAL | Netcore NBR100V2 ACL unauthenticated.json uci.apply authorization |
| CVE-2026-101002 | 9.9 CRITICAL | Netcore NBR200V2 Tools Ping network_tools system os command injection |
No comments yet