Cyber & AI intelligence
Wasteland.
Briefs indexed2910
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-101000 2026-09-28

Netcore NBR100V2 Router Flaw Lets Unauthenticated Attackers Reach uci.apply (CVE-2026-101000)

"CVE-2026-101000 is a critical missing-authorization flaw in the ACL Handler of the Netcore NBR100V2 router firmware. It can be triggered remotely, a public exploit exists, and the vendor has not responded."

CVE-2026-101000 is a critical missing-authorization flaw in the ACL Handler of the Netcore NBR100V2 router firmware. It can be triggered remotely, a public exploit exists, and the vendor has not responded.

What Is It

The flaw is in the uci.apply function, which is exposed through /usr/share/rpcd/acl.d/unauthenticated.json in the device's ACL Handler component. An attacker can manipulate the section argument to reach functionality that should require authorization. The attack can be started over the network.

The CNA (VulDB) classifies the weakness as CWE-862 (Missing Authorization) and CWE-863 (Incorrect Authorization). The public write-up that NVD references describes it as UCI configuration tampering.

Why It Matters

What's Vulnerable

The supplied data lists no other versions as affected or unaffected.

Patch Status

The sources do not mention a patch or vendor advisory. According to the CNA, Netcore was contacted early about the disclosure but "did not respond in any way." NVD lists the record's status as "Received," published 2026-09-28. There is no CISA KEV entry, so no federal required action or due date applies.

Organizations running NBR100V2 firmware 1.3.240614.030928 should treat the device as unpatched and follow the references below for updates.

Sources