Sceawere

Vulnerability Detail

CVE-2026-94100UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Netcore NBR200V2 Buffer Overflow

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
2h ago
Vendor
Netcore
Product
NBR200V2
Attack Type
Buffer Overflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-09-21T01:16:30.170Z",
  "pubdate": "2026-09-21T01:16:30.170Z",
  "executiveSummary": "A critical buffer overflow vulnerability has been identified in the Netcore NBR200V2 router, specifically within the WAN VLAN Reconfiguration component.\nThe vulnerability resides in the wan_config_set_vlan function within the /usr/bin/routerd binary. It allows a remote, unauthenticated attacker to trigger a buffer overflow by manipulating the vlan_wanX.ports argument.\nSuccessful exploitation of this flaw can lead to arbitrary code execution, system compromise, or a denial-of-service state for the affected router.\nBecause the vulnerability is remotely exploitable and proof-of-concept exploit code is publicly available, the risk to exposed devices is high.\nThe vendor has been notified but has not provided a patch or response, leaving systems vulnerable to active exploitation.",
  "technicalDetails": "The vulnerability is a buffer overflow condition located in the /usr/bin/routerd binary, specifically within the wan_config_set_vlan function responsible for WAN VLAN configuration.\nThe root cause of the vulnerability is the improper handling of user-supplied input provided to the vlan_wanX.ports argument. The function fails to perform adequate bounds checking on the data before copying it into a fixed-size memory buffer.\nExploitation occurs when an attacker crafts a malicious request containing an overly long string as the value for the vlan_wanX.ports parameter. When the routerd process parses this argument and passes it to the vulnerable function, the excessive input data overflows the allocated stack or heap buffer.\nBy carefully structuring the malicious input, an attacker can overwrite adjacent memory, including critical data such as function return addresses or control flow pointers on the stack.\nThis allows the attacker to redirect the execution flow of the routerd process to arbitrary code, which can be included as part of the malicious payload (shellcode) or pointed toward existing executable code (Return-Oriented Programming).\nThe attack vector is network-based, meaning the device does not require physical access to be compromised, and the attack can be performed remotely. Based on the nature of the interface, the exploit likely bypasses authentication requirements, as such configuration endpoints are often accessible without active session tokens in this class of devices.\nSuccessful exploitation results in post-exploitation impact ranging from persistent denial-of-service, caused by process crashing, to full remote code execution with the privileges of the routerd process, which typically runs with elevated system permissions.\nGiven that public exploit code exists, the effort required for an attacker to compromise vulnerable Netcore NBR200V2 units running version 1.3.241127.071246 is minimal, significantly increasing the probability of exploitation in the wild."
}
CVE-2026-94100: Netcore NBR200V2 Buffer Overflow (CRITICAL Severity, CVSS: 9.9) | Sceawere