TopVuln

High-risk vulnerability digests

CVE-2026-4840

  • HIGH

Details

CVSS v3
8.8
CVSS v4
7.4
CVSS v2
9.0
NVD published
2026-03-26 05:16:40
Affected versions
Netcore Power 15AX firmware up to 3.0.0.6938
Summary
This vulnerability affects the diagnostic tool interface of the Netcore Power 15AX router's management web interface. Improper sanitization of the IpAddr argument in the setTools function allows remote attackers to inject and execute arbitrary operating system commands. Public exploit code for this vulnerability has been released, and the vendor has not responded to disclosure requests.
Remediation
Restrict access to the router's web management interface to only trusted internal IP addresses immediately. Since no official patch is available from the vendor, consider replacing the affected router with a supported alternative. Monitor for unauthorized administrative access and unusual outbound traffic from the device.
Exploit info
The exploit has been released to the public (for example, see https://app.opencve.io/cve/CVE-2026-4840 or https://vuldb.com/). | Potential exploit details can be searched in Exploit-DB or GitHub: https://www.exploit-db.com/search?cve=CVE-2026-4840 | https://github.com/search?q=CVE-2026-4840+exploit

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.