Missing Authorization Vulnerability in Netcore NBR100V2 by Netcore
CVE-2026-101000
Key Information:
Badges
What is CVE-2026-101000?
A significant vulnerability exists in the Netcore NBR100V2 router, specifically within the ACL Handler component. The flaw is found in the 'uci.apply' function of the unauthenticated.json file. By manipulating the argument section, an attacker is able to bypass necessary authorization checks remotely, potentially enabling them to exploit the device. Despite attempts to inform the vendor about this issue, there has been no response, raising concerns about the potential for misuse of this vulnerability.
Affected Version(s)
NBR100V2 1.3.240614.030928
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
