在 Netcore NBR200V2 1.3.241127.071246 中已发现一个漏洞。该漏洞影响的是固件升级 CGI 端点组件中 /www/cgi-bin/upgrade 文件的未知代码。攻击者可通过操纵 QUERY_STRING 参数实施命令注入攻击。该攻击可远程执行。漏洞利用代码已公开,可能被利用。研究人员在披露此漏洞时已提前联系供应商,但供应商未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94101 | 9.9 CRITICAL | Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow |
| CVE-2026-94100 | 9.9 CRITICAL | Netcore NBR200V2 WAN VLAN Reconfiguration routerd wan_config_set_vlan buffer overflow |
| CVE-2026-94099 | 9.9 CRITICAL | Netcore NBR200V2 Backup Restore restore.cgi command injection |
No comments yet