Skip to finding
important · Firmware / Wi-Fi

One unauthenticated LAN request executes commands as root on a Netcore NAP930.

Affects

Netcore NAP930, a Wi-Fi 6 business access point running OpenWrt-derived embedded firmware.

The network_tools CGI evaluates the sid value before checking the session, so closing its quoted value appends a root shell command.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, October 4, 2026