VYPR
Vendor

Netcore

Products
12
CVEs
49
Across products
55
Status
Private

Products

12

Recent CVEs

49
View all 49 CVEs →
  • CVE-2026-102240CriSep 29, 2026
    risk 0.65cvss 10.0epss 0.02

    A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote.…

  • CVE-2026-101077CriSep 28, 2026
    risk 0.65cvss 10.0epss 0.01

    A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used.…

  • CVE-2026-101076CriSep 28, 2026
    risk 0.65cvss 10.0epss 0.02

    A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit…

  • CVE-2026-101075CriSep 28, 2026
    risk 0.65cvss 10.0epss 0.02

    A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of…

  • CVE-2026-101072CriSep 28, 2026
    risk 0.65cvss 10.0epss 0.02

    A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is…

  • CVE-2026-101001CriSep 28, 2026
    risk 0.65cvss 10.0epss 0.03

    A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to…

  • CVE-2026-101000CriSep 28, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible…

  • CVE-2026-94097CriSep 21, 2026
    risk 0.65cvss 10.0epss 0.03

    A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of…

  • CVE-2025-34117CriJul 16, 2025
    risk 0.65cvss —epss 0.27

    A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the presence of an undocumented backdoor listener on UDP port 53413. Exact version boundaries remain undocumented. An unauthenticated…

  • CVE-2026-101074CriSep 28, 2026
    risk 0.64cvss 9.8epss 0.01

    A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be…

  • CVE-2026-101002CriSep 28, 2026
    risk 0.64cvss 9.9epss 0.02

    A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be…

  • CVE-2026-94101CriSep 21, 2026
    risk 0.64cvss 9.9epss 0.01

    A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possible to initiate the attack…

  • CVE-2026-94100CriSep 21, 2026
    risk 0.64cvss 9.9epss 0.01

    A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can lead to buffer overflow. The…

  • CVE-2026-94099CriSep 21, 2026
    risk 0.64cvss 9.9epss 0.02

    A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is…

  • CVE-2026-94096CriSep 21, 2026
    risk 0.64cvss 9.9epss 0.02

    A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack…

  • CVE-2026-94095CriSep 21, 2026
    risk 0.64cvss 9.9epss 0.02

    A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection.…

  • CVE-2026-94098CriSep 21, 2026
    risk 0.59cvss 9.1epss 0.02

    A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack…

  • CVE-2026-4840HigMar 26, 2026
    risk 0.58cvss 8.8epss 0.04

    A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cgi of the component Diagnostic Tool Interface. Performing a manipulation of the argument IpAddr results in os command injection.…

  • CVE-2026-76862HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components. Attackers can inject crafted arguments into…

  • CVE-2026-76861HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values. An attacker can submit crafted input to this cgi endpoint to overflow the stack buffer and potentially execute…