Netcore NBR1005GPEV2
cpe:2.3:h:netis-systems:netcore_router:*:*:*:*:*:*:*, +1 more
- <= 20250508
A critical command injection vulnerability has been identified in several Netcore router models, including the NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2, and NBR200V2, all running firmware prior to 20250508. The vulnerability arises in the HTTP Header Handler component, specifically within the 'passwd_set' function of the 'routerd' file. This issue allows for arbitrary command execution by manipulating the 'pwd' argument, and can be exploited remotely.
Exploitation of this vulnerability allows for arbitrary command execution on the affected device.
The vulnerability can be reproduced by sending a POST request to '/ubus' with a JSON payload that includes the 'passwd_set' method. The 'pwd' parameter can be crafted to include a command, such as 'mkdir', which will be executed on the device. This exploitation can be automated with a script or tool that interacts with the device's web interface.
Netcore users are advised to contact Netcore (Netis Technology) technical support to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.