Sceawere

Vulnerability Detail

CVE-2026-101000UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Netcore NBR100V2 Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
4h ago
Vendor
Netcore
Product
NBR100V2
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-09-28T05:16:30.270Z",
  "pubdate": "2026-09-28T05:16:30.270Z",
  "executiveSummary": "A critical missing authorization vulnerability exists in the Netcore NBR100V2 router, specifically within the ACL handler configuration. This vulnerability allows remote, unauthenticated attackers to manipulate the uci.apply function via the /usr/share/rpcd/acl.d/unauthenticated.json file. By exploiting this flaw, an attacker can bypass access control mechanisms to execute unauthorized actions, effectively overriding system settings or modifying device configurations without valid credentials. The risk is significant as the exploit is publicly available, and the vendor has remained unresponsive to disclosure attempts, leaving the device perimeter unprotected against unauthorized administrative control. Successful exploitation leads to total compromise of the device's configuration integrity and potential remote command execution scenarios.",
  "technicalDetails": "The vulnerability resides within the ACL (Access Control List) handling mechanism of the Netcore NBR100V2 firmware version 1.3.240614.030928. Specifically, the configuration file located at /usr/share/rpcd/acl.d/unauthenticated.json defines the access policies for remote procedure calls (RPC). An improper configuration within this JSON definition grants unauthenticated access to the uci.apply function, a critical system utility responsible for committing Unified Configuration Interface (UCI) changes to the router's active environment.\nThe root cause is an insecure ACL definition that exposes administrative RPC methods to the unauthenticated namespace. Under normal conditions, sensitive functions such as uci.apply should require elevated privileges and active authentication sessions. However, due to the permissive policy defined in the unauthenticated.json file, the system fails to validate the caller's identity or session status when invoking this specific function.\nExploitation is conducted remotely over the network. An attacker can craft a malicious RPC request targeting the uci.apply function by manipulating the 'section' argument. Because the ACL handler does not enforce authorization, the router processes the payload as a legitimate command. The attack flow involves the attacker sending an unauthorized RPC message to the device's management interface. Upon reaching the uci.apply function, the system executes the specified configuration changes as if they were initiated by an authorized administrator.\nThe impact of this vulnerability is severe. Since uci.apply is the interface through which the system applies system-wide configuration settings, an attacker can manipulate network routing, modify firewall rules, change administrative passwords, or disable security features. By leveraging this vulnerability, an adversary can gain persistence, facilitate man-in-the-middle attacks by altering DNS settings, or open further backdoors into the network. Given that the exploit methodology is publicly disclosed, the barrier to entry for potential attackers is extremely low. The lack of vendor response means that automated firmware remediation is currently unavailable, necessitating manual defensive intervention by network administrators to mitigate the risk of exploitation."
}
CVE-2026-101000: Netcore NBR100V2 Missing Authorization Vulnerability (CRITICAL Severity, CVSS: 10.0) | Sceawere