A vulnerability was found in Netcore NBR1005GPEV2, NBR200V2 and B6V2 up to 20250508 and classified as critical. This issue affects the function tools_ping of the file /usr/bin/network_tools. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
History

Thu, 29 May 2025 07:30:00 +0000

Type Values Removed Values Added
References

Thu, 29 May 2025 07:15:00 +0000

Type Values Removed Values Added
References

Wed, 28 May 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 25 May 2025 11:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Netcore NBR1005GPEV2, NBR200V2 and B6V2 up to 20250508 and classified as critical. This issue affects the function tools_ping of the file /usr/bin/network_tools. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Title Netcore NBR1005GPEV2/NBR200V2/B6V2 network_tools tools_ping command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-05-25T11:31:04.116Z

Updated: 2025-05-29T07:00:52.075Z

Reserved: 2025-05-24T13:37:03.230Z

Link: CVE-2025-5147

cve-icon Vulnrichment

Updated: 2025-05-27T14:21:45.604Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-25T12:15:19.260

Modified: 2025-05-29T07:15:25.330

Link: CVE-2025-5147

cve-icon Redhat

No data.