CVE-2026-94095 is an OS command-injection vulnerability in Netcore NBR200V2 firmware version 1.3.241127.071246. The Traceroute Diagnostic Feature passes a user-controlled URL argument to a system command without adequate neutralization of shell metacharacters or other command elements. An authenticated remote attacker with low privileges can supply a crafted argument to cause execution of attacker-controlled operating-system commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This four-file repository contains a standalone Python 3 proof-of-concept and duplicated Markdown disclosure material for CVE-2026-94095. The target is Netcore NBR200V2 firmware V1.3.241127.071246. The vulnerability is an authenticated remote OS command injection in the ubus JSON-RPC traceroute diagnostic path: attacker-controlled `url` data reaches `tools_traceroute()`, which embeds it in a shell command passed to `system()` without sanitization. `poc.py` uses only Python standard-library modules, can authenticate through ubus `session.login` to recover a session ID, and then POSTs a crafted JSON-RPC call to `<target>/ubus`. It accepts an arbitrary `--cmd` value and injects it using shell separators and a comment character. README.md and CVE-2026-94095.md describe the underlying binary, reverse-engineered call chain, a reboot demonstration, related CVEs, and mitigations; LICENSE is MIT. No external exploitation framework or hard-coded victim host is present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remotely exploitable command-injection vulnerability in the Traceroute Diagnostic Feature's /usr/bin/network_tools functionality on Netcore NBR200V2 firmware version 1.3.241127.071246. Manipulation of the url argument can trigger command injection.
A remotely reachable command-injection vulnerability in the Traceroute Diagnostic Feature of Netcore NBR200V2 firmware version 1.3.241127.071246. Manipulation of the url argument passed to /usr/bin/network_tools can result in command execution. Authentication is required, according to the CVSS vectors, and public exploit disclosure is reported.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.