CVE-2026-4840Disclosure

HIGHCVSS 7.4 · HIGH

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cgi of the component Diagnostic Tool Interface. Performing a manipulation of the argument IpAddr results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-26: 4PoC Mentioned / Linked · 2026-03-26: 1Exploit Tool / Code · 2026-03-26: 1Active Exploitation · 2026-03-26: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 403-26
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
General
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4840 A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cgi of the component … https://www.cve.org/CVERecord?id=CVE-2026-4840

    Post summary

    A new vulnerability (CVE-2026-4840) has been identified in Netcore Power 15AX, impacting the setTools function within /bin/netis.cgi on versions up to 3.0.0.6938.

    00010114
    56.8K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    CISA warns of active exploitation of six new vulnerabilities in its catalog, including CVE-2026-4840. Attackers can execute arbitrary commands via Netcore Power 15AX Diagnostic Tool. Patch immediately to prevent system compromise. #CyberSecurity #InfoSec https://t.co/BHeWqLpVhN

    Post summary

    CISA reports CVE-2026-4840 is actively exploited, allowing command execution through Netcore Power 15AX Diagnostic Tool, and urges immediate patching.

    0000042
    50 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4840: HIGH] Critical security flaw in Netcore Power 15AX up to 3.0.0.6938 allows for remote os command injection via manipulated IpAddr argument in /bin/netis.cgi Diagnostic Tool Interface component....#cve,CVE-2026-4840,#cybersecurity https://cvefind.com/CVE-2026-4840

    Post summary

    The post announces a high‑severity remote OS command injection flaw in Netcore Power 15AX up to 3.0.0.6938, detailing the vulnerable argument and providing a link for further information.

    0000048
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-4840 - High A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cgi of the component Diagnostic Tool Interfac... https://www.thehackerwire.com/vulnerability/CVE-2026-4840/ https://t.co/65sxFw3m9j

    Post summary

    The tweet announces a newly discovered CVE-2026-4840 in Netcore Power, noting the affected function and file, but provides no PoC, exploit tool, or patch information.

    0000045
    148 followersView on X

Explore more