CVE-2026-94101
9.9Netcore · NBR200V2
A buffer overflow vulnerability in the Netcore NBR200V2 router allows remote attackers to execute arbitrary code via the wan_num argument in the vlan_load_form_uci function.
Executive summary
A critical buffer overflow vulnerability in Netcore NBR200V2 routers allows for remote code execution by authenticated attackers, posing a severe threat to network infrastructure.
Vulnerability
This is a memory corruption vulnerability (CWE-120) triggered by improper handling of the wan_num argument within the /usr/bin/routerd binary. The vulnerability is exploitable by any authenticated user over the network.
Business impact
The CVSS score of 9.9 reflects the extreme severity of this flaw, as it grants an attacker full control over the affected router. Successful exploitation could lead to total compromise of network traffic, unauthorized access to internal resources, and significant disruption of business operations. Given that the vendor has not provided a response or patch, the risk of persistent, undetected compromise is high.
Remediation
Immediate Action: Since no official patch is available, restrict access to the device management interface to trusted administrative networks only, and disable remote management features if they are not strictly required.
Proactive Monitoring: Inspect system logs for unusual crash events related to the routerd service and monitor network traffic for unexpected patterns originating from internal management segments.
Compensating Controls: Deploy a Web Application Firewall or intrusion detection rules to inspect incoming requests for malformed parameters targeting the wan_num argument, providing a virtual patch layer.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the referenced security research documentation.
Analyst recommendation
Given the critical CVSS severity and the presence of a public proof-of-concept, users of the Netcore NBR200V2 must prioritize isolating these devices from untrusted network segments immediately. Because no vendor-supplied fix is currently available, organizations should consider these devices high-risk and implement strict network-level segmentation until the manufacturer releases a firmware update.
More Netcore CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by FirmHarness (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.
- VDB-408030 | Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow Vulnerability database entry
- VDB-408030 | CTI Indicators (IOB, IOC, IOA)
- CVE-2026-94101 | CVE Analysis and Report Third-party advisory
- Submit #892995 | netcore NBR200V2 V1.3.241127.071246 Buffer Overflow Third-party advisory
- Exploit / PoC