📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 4h Global supply_chain Software Development and Technology HIGH 9h Global apt Government/Critical Infrastructure CRITICAL 11h Global vulnerability Enterprise Software / Data Analytics CRITICAL 12h Global vulnerability Artificial Intelligence and Technology HIGH 15h Global general Technology and Artificial Intelligence MEDIUM 19h Global general Technology and Artificial Intelligence HIGH 20h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 4h Global supply_chain Software Development and Technology HIGH 9h Global apt Government/Critical Infrastructure CRITICAL 11h Global vulnerability Enterprise Software / Data Analytics CRITICAL 12h Global vulnerability Artificial Intelligence and Technology HIGH 15h Global general Technology and Artificial Intelligence MEDIUM 19h Global general Technology and Artificial Intelligence HIGH 20h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 4h Global supply_chain Software Development and Technology HIGH 9h Global apt Government/Critical Infrastructure CRITICAL 11h Global vulnerability Enterprise Software / Data Analytics CRITICAL 12h Global vulnerability Artificial Intelligence and Technology HIGH 15h Global general Technology and Artificial Intelligence MEDIUM 19h Global general Technology and Artificial Intelligence HIGH 20h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2026-4840

High
A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cgi of the component Diagnostic Tool Interface. Perfo
CWE-77 — Weakness Type
Published: Mar 26, 2026  ·  Modified: Apr 2, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cgi of the component Diagnostic Tool Interface. Performing a manipulation of the argument IpAddr results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

🤖 AI Executive Summary

CVE-2026-4840 is a critical OS command injection vulnerability in Netcore Power 15AX devices up to version 3.0.0.6938, exploitable through the Diagnostic Tool Interface via the IpAddr parameter. With a CVSS score of 8.8 and public exploit availability, this poses immediate risk to network infrastructure across Saudi Arabia. The vendor's non-responsiveness leaves affected organizations without official patches, requiring urgent compensating controls.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 23, 2026 11:51
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability critically impacts Saudi telecommunications infrastructure (STC, Mobily, Zain), government networks (NCA, CITC), banking sector (SAMA-regulated institutions), and energy infrastructure (ARAMCO, SEC). Netcore devices are widely deployed in ISP backbone networks and enterprise environments across Saudi Arabia. Successful exploitation enables complete system compromise, lateral movement, and potential disruption of critical services. The public exploit availability significantly increases attack likelihood against unpatched systems.
🏢 Affected Saudi Sectors
Telecommunications (STC, Mobily, Zain) Government (NCA, CITC, Ministry of Interior) Banking and Financial Services (SAMA-regulated) Energy (ARAMCO, SEC) Healthcare (MOH) Critical Infrastructure ISP and Network Service Providers
⚖️ Saudi Risk Score (AI)
9.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Netcore Power 15AX devices in your network using asset discovery tools and SNMP scanning
2. Isolate affected devices from internet-facing networks immediately
3. Implement network segmentation to restrict access to /bin/netis.cgi endpoint
4. Enable comprehensive logging and monitoring of diagnostic tool interface access

COMPENSATING CONTROLS:
1. Deploy WAF/IPS rules to block requests containing command injection patterns to /bin/netis.cgi (monitor for: |, ;, &, $(), backticks, newline characters in IpAddr parameter)
2. Restrict administrative access to diagnostic interfaces via IP whitelisting
3. Disable the Diagnostic Tool Interface if not actively required
4. Implement rate limiting on diagnostic endpoints
5. Monitor for suspicious process execution originating from netis.cgi

DETECTION RULES:
1. Alert on HTTP requests to /bin/netis.cgi with special characters in IpAddr parameter
2. Monitor for unexpected child processes spawned by netis.cgi process
3. Track failed authentication attempts to diagnostic interfaces
4. Log all parameter modifications to setTools function

PATCHING STRATEGY:
1. Contact Netcore vendor directly for emergency patches or workarounds
2. Evaluate alternative network diagnostic solutions
3. Plan device replacement if vendor support is unavailable
4. Document all compensating controls implemented
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع أجهزة Netcore Power 15AX في شبكتك باستخدام أدوات اكتشاف الأصول وفحص SNMP
2. عزل الأجهزة المتأثرة عن الشبكات المتصلة بالإنترنت فوراً
3. تطبيق تقسيم الشبكة لتقييد الوصول إلى نقطة نهاية /bin/netis.cgi
4. تفعيل السجلات الشاملة ومراقبة الوصول إلى واجهة أداة التشخيص

الضوابط التعويضية:
1. نشر قواعد WAF/IPS لحجب الطلبات التي تحتوي على أنماط حقن الأوامر إلى /bin/netis.cgi
2. تقييد الوصول الإداري إلى واجهات التشخيص عبر قائمة بيضاء للعناوين
3. تعطيل واجهة أداة التشخيص إذا لم تكن مطلوبة بنشاط
4. تطبيق تحديد معدل على نقاط نهاية التشخيص
5. مراقبة تنفيذ العمليات المريبة من netis.cgi

قواعد الكشف:
1. تنبيهات على طلبات HTTP إلى /bin/netis.cgi بأحرف خاصة في معامل IpAddr
2. مراقبة العمليات الفرعية غير المتوقعة التي تم إنشاؤها بواسطة عملية netis.cgi
3. تتبع محاولات المصادقة الفاشلة على واجهات التشخيص
4. تسجيل جميع تعديلات المعاملات على وظيفة setTools

استراتيجية التصحيح:
1. الاتصال المباشر ببائع Netcore للحصول على تصحيحات طوارئ أو حلول بديلة
2. تقييم حلول تشخيص الشبكة البديلة
3. التخطيط لاستبدال الجهاز إذا كان دعم البائع غير متاح
4. توثيق جميع الضوابط التعويضية المطبقة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Information security policies and procedures A.8.1.1 - User access management A.12.2.1 - Change management procedures A.12.4.1 - Event logging and monitoring A.13.1.1 - Network security perimeter
🔵 SAMA CSF
ID.AM-2 - Asset management and inventory PR.AC-1 - Access control policy PR.PT-1 - Security awareness and training DE.CM-1 - System monitoring and anomaly detection RS.MI-1 - Incident response procedures
🟡 ISO 27001:2022
A.5.1 - Management direction for information security A.8.1 - User access management A.12.2 - Change management A.12.4 - Logging and monitoring A.13.1 - Network security
🟣 PCI DSS v4.0.1
Requirement 1.1 - Firewall configuration standards Requirement 2.1 - Default security parameters Requirement 6.2 - Security patches and updates Requirement 10.2 - Logging and monitoring
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-77
EPSS0.20%
Exploit No
Patch ✗ No
Published 2026-03-26
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
9.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-77
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.