Skip to finding
important · Embedded firmware

Public firmware-emulation code shows unauthenticated NBR200V2 requests reaching a root shell.

Affects

Netcore NBR200V2, an embedded business router managed through its uHTTPd web interface.

The network-tools handler evaluates attacker-controlled diagnostic input before checking authentication, and the emulated web service runs as root.

Detail and 2 sources

Firmware configuration lists uHTTPd on ports 80, 443, and 23355, but stock-hardware execution and default WAN reachability have not been established.

Chain to watch
Confirm the listening interfaces on a stock NBR200V2 running V1.3.241127.071246.→↓Send a benign unauthenticated network-tools request containing a shell metacharacter.→↓Record authentication behavior, command output, and process UID.→↓The published execution result comes from QEMU or chroot rather than stock hardware, and default WAN exposure is unknown.
Unverified chainReproduce a benign identity command on stock hardware while capturing listening interfaces and resulting UID.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 28, 2026