A critical command injection vulnerability affects Netcore NBR200V2 version 1.3.241127.071246, according to CVE Record and NVD entries . The vulnerability affects the CGI of diagnostic tools and could allow remote command execution on a vulnerable device.

The vulnerability has been assigned the identifier CVE-2026-94097 and is listed as a special character spoofing issue in commands. The Netcore NBR200V2 is used as a wireless router, so exposing the management to the internet significantly increases the risk for networks that do not have additional access restrictions.
See also: Totolink A3002MU: Three new vulnerabilities allow remote attacks
What CVE-2026-94097 reveals
According to the CVE Record, the issue is located in the file /www/cgi-bin/network_tools, in the element described as CGI Diagnostic Endpoint. The processing of the param, key , and val does not properly isolate the data entered by the user. With a properly crafted request, an attacker can cause the service to execute operating system commands.
The listing mentions remote exploitation without requiring user privileges. It also notes that an exploit has been made public and can be used. This does not equate to a confirmed active exploit on the internet, but it makes immediate isolation of devices particularly important.

CVEFeed lists only 1.3.241127.071246 as the affected version and notes that the manufacturer has been updated, with no response recorded. There is no specific patch version or official upgrade instructions available in the listing. NVD classifies the vulnerability as CWE-74 and CWE-77 and displays a CVSS-BT score of 9.3, critical.
See also: Researchers warn of backdoors in Netcore/Netis Routers
What are the risks to a network?
Command injection into a router can give access to functions that are located at the boundary between the internet and the internal network. If the administrator has left the CGI endpoint accessible from the WAN, the attack can be launched without a physical presence on site. From there, the adversary could change settings, monitor traffic, or use the router as an entry point for other devices.
The CVE Record does not document breach incidents or provide tracking indicators. The SecNews technical team therefore emphasizes the distinction between publicly available exploits and active exploitation. Organizations should treat the finding as an emergency, without attributing unconfirmed events to the entry.

See also: 3BB Network: MeshCentral Exploit for Root Access
Immediate measures for Netcore NBR200V2
Until an official fix is released, administrators should block access to CGI diagnostic tools from the internet and allow management only from a trusted internal network or secure remote access channel. They should also change unique management passwords, disable unused services, and check logs for unusual calls to the endpoint.
Netcore NBR200V2 owners should note the exact firmware version, monitor the manufacturer's website for an announcement, and immediately apply any official package that becomes available. If the device cannot be isolated or supported, replacing it is a safer option. The SecNews editorial team will review the case when a new technical update is available.

The assessment should not be limited to the router itself. Administrators should check whether the Netcore NBR200V2 shares credentials with other devices, whether it uses port forwarding to the internal network, and whether new processes or changes to DNS settings appear. A copy of the current configuration helps with safe recovery, without keeping it in an unprotected location.
In case of suspicious activity, the device should be isolated and available logs collected before rebooting or factory resetting. Changing passwords should be done from a clean computer and extended to accounts that may have been affected. Resetting without prior documentation can destroy useful data for analysis.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
There is no clear guidance yet published confirming which version will fix the issue. Therefore, security teams should not assume an upgrade is secure just because it is newer, but should request written confirmation from the vendor and verify the version after installation.
CVE -2026-94097 combines remote exploitation, a public exploit, and the absence of a documented fix. Temporarily reducing exposure, monitoring logs, and immediately contacting the vendor are the key steps until a safe upgrade is available. The same process should be repeated on every affected device in the organization.
