important · Embedded firmware
Public firmware-emulation code shows unauthenticated NBR200V2 requests reaching a root shell.
Affects
Netcore NBR200V2, an embedded business router managed through its uHTTPd web interface.
The network-tools handler evaluates attacker-controlled diagnostic input before checking authentication, and the emulated web service runs as root.
Detail and 2 sources
Firmware configuration lists uHTTPd on ports 80, 443, and 23355, but stock-hardware execution and default WAN reachability have not been established.
Chain to watch
Confirm the listening interfaces on a stock NBR200V2 running V1.3.241127.071246.→↓Send a benign unauthenticated network-tools request containing a shell metacharacter.→↓Record authentication behavior, command output, and process UID.→↓The published execution result comes from QEMU or chroot rather than stock hardware, and default WAN exposure is unknown.
Unverified chainReproduce a benign identity command on stock hardware while capturing listening interfaces and resulting UID.