天下漏洞,尽知其名
CRITICAL

CVE-2026-101002 Netcore NBR200V2 操作系统命令注入漏洞

影响攻击者可远程执行任意系统命令

AI 研判

Netcore NBR200V2 路由器固件 1.3.241127.071246 版本的 network_tools 组件中,Ping 工具处理函数对 url 参数未做充分过滤,存在操作系统命令注入漏洞。该漏洞可被远程利用,且公开利用代码已发布,厂商未作回应。

影响范围

Netcore NBR200V2

Netcore NBR200V2 固件版本 1.3.241127.071246;其他版本是否受影响暂无公开信息。

漏洞详情

漏洞位于 /usr/bin/network_tools 中负责 Ping 工具处理的 system 函数。程序在拼接系统命令时直接使用了用户可控的 url 参数,未进行转义或白名单校验,导致攻击者可注入 shell 元字符执行任意命令。攻击者通过网络发送特制请求即可触发,无需本地访问。

利用条件与风险

利用前提是目标设备的管理接口或相关服务可被远程访问,且攻击者能控制 url 参数。由于利用代码已公开且 CVSS 高达 9.9,实战中被扫描和攻击的风险很高。

修复建议

官方尚未发布修复版本,建议关注 Netcore 官方公告。临时缓解措施包括限制管理接口的访问来源、关闭不必要的远程管理功能,或对 url 参数进行严格过滤。

原始情报

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.