VYPR
advisoryPublished Sep 28, 2026· 1 source

Netcore NBR200V2/NBR100V2: Three Critical Command Injection and Auth Bypass Flaws Disclosed Together

Key findings • Three critical vulnerabilities disclosed on September 28, 2026, affecting Netcore NBR200V2 and NBR100V2 devices. • All three vulnerabilities allow for remote exploitation, with…

Key findings

  • Three critical vulnerabilities disclosed on September 28, 2026, affecting Netcore NBR200V2 and NBR100V2 devices.
  • All three vulnerabilities allow for remote exploitation, with two leading to OS command injection and one to missing authorization.
  • Affected versions include Netcore NBR200V2 1.3.241127.071246 and NBR100V2 1.3.240614.030928.
  • The vulnerabilities were disclosed within a one-hour window, indicating a concentrated disclosure event.

On September 28, 2026, a batch of three critical vulnerabilities was disclosed for Netcore devices, all stemming from a single-hour disclosure window. These flaws, affecting Netcore NBR200V2 and NBR100V2 models, present significant remote command injection and missing authorization risks to users. The vulnerabilities were reported on the same day, highlighting a concentrated disclosure event that demands immediate attention from administrators.

Two of the vulnerabilities, CVE-2026-101002 and CVE-2026-101001, are critical OS command injection flaws affecting the Netcore NBR200V2. CVE-2026-101002 resides in the Tools Ping Handler component, specifically within the /usr/bin/network_tools file, where manipulation of the 'url' argument can lead to command injection. Similarly, CVE-2026-101001 impacts the Web Management Interface, located in /www/cgi-bin/network_tools, where altering the 'QUERY_STRING' argument enables remote command execution. Both of these vulnerabilities carry a CVSSv3 score of 9.9 and 10.0 respectively and can be exploited remotely.

The third vulnerability, CVE-2026-101000, also rated as critical with a CVSSv3 score of 10.0, affects the Netcore NBR100V2. This flaw is found in the ACL Handler component, specifically within /usr/share/rpcd/acl.d/unauthenticated.json at the uci.apply function. Manipulation of the 'section' argument in this context results in missing authorization, allowing for remote exploitation.

The disclosures indicate that these vulnerabilities are exploitable remotely, posing a significant threat to the security posture of organizations using the affected Netcore devices. While the provided details do not specify active exploitation in the wild or name specific threat actors, the critical nature and remote exploitability of these flaws warrant prompt remediation.

The affected versions mentioned are Netcore NBR200V2 1.3.241127.071246 and Netcore NBR100V2 1.3.240614.030928. Specific patch details or updated firmware versions are not provided in the initial disclosure, but users are strongly advised to consult Netcore's official security advisories for the latest information on patches and mitigation strategies.

The simultaneous disclosure of these critical vulnerabilities underscores the importance of timely patching and security updates for network infrastructure devices. Administrators managing Netcore NBR200V2 and NBR100V2 devices should prioritize investigating and applying any available security updates to protect their networks from potential compromise. Further monitoring of Netcore's security communications is recommended.

Synthesized by Vypr AI