CVE-2026-101000
Received Received - Intake

ACL Authorization Bypass in Netcore NBR100V2

Vulnerability report for CVE-2026-101000, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nbr100v2 1.3.240614.030928

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101000 is an unauthenticated configuration-tampering vulnerability in Netcore NBR100V2 routers running firmware version V1.3.240614.030928. It allows remote attackers on the local network to modify router settings without credentials when the device is in a factory-default or unconfigured state. The flaw exists due to missing authorization checks in the uci.apply function of the ACL Handler component.

Detection Guidance

Check if your Netcore NBR100V2 router is in an unconfigured state by verifying if system.@system[0].initialized equals 0. Use the command: uci get system.@system[0].initialized. If it returns 0, the device is vulnerable.

Monitor network traffic for POST requests to /ubus with uci.set or uci.apply methods targeting unauthenticated.json ACL files.

Inspect router logs for unauthorized configuration changes, especially in WiFi settings or firmware update sources.

Impact Analysis

An attacker could change WiFi credentials (SSID, encryption key) to steal network access or create rogue access points. They could also tamper with firmware update settings, enabling supply-chain attacks when the device auto-updates. This requires the router to be unconfigured (factory default or after reset).

Compliance Impact

This vulnerability allows remote attackers to modify router configurations without authentication, potentially exposing sensitive network data or enabling unauthorized access. Such unauthorized changes could lead to violations of data protection requirements under GDPR or HIPAA if the router handles personal or health information. The lack of access controls during unconfigured states increases the risk of non-compliance with security and privacy standards.

Mitigation Strategies

Immediately configure the router through the web interface to set system.@system[0].initialized to 1, which restricts unauthenticated access.

Disable the /ubus JSON-RPC endpoint if not required by editing the uhttpd configuration.

Update the router firmware to the latest version if an official patch is available.

Isolate the router from untrusted networks until mitigation is complete.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101000. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart