CVE-2026-101000 is a critical missing-authorization flaw in the ACL Handler of the Netcore NBR100V2 router firmware. It can be triggered remotely, a public exploit exists, and the vendor has not responded.
What Is It
The flaw is in the uci.apply function, which is exposed through /usr/share/rpcd/acl.d/unauthenticated.json in the device's ACL Handler component. An attacker can manipulate the section argument to reach functionality that should require authorization. The attack can be started over the network.
The CNA (VulDB) classifies the weakness as CWE-862 (Missing Authorization) and CWE-863 (Incorrect Authorization). The public write-up that NVD references describes it as UCI configuration tampering.
Why It Matters
- CVSS 3.1: 10.0 (CRITICAL):
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The attack runs over the network, is low-complexity, and needs no privileges or user interaction. Scope is changed, and the impact on confidentiality, integrity and availability is high. - CVSS 4.0: 9.3 (CRITICAL), with exploit maturity rated Proof-of-Concept.
- CVSS 2.0: 10.0
- NVD says the exploit "has been publicly disclosed and may be utilized."
- KEV status: CVE-2026-101000 is not in CISA's Known Exploited Vulnerabilities catalog. The supplied sources do not confirm active exploitation in the wild.
What's Vulnerable
- Vendor: Netcore
- Product: NBR100V2
- Affected version: 1.3.240614.030928
- Component: ACL Handler (
uci.apply,/usr/share/rpcd/acl.d/unauthenticated.json) - CPE:
cpe:2.3:a:netcore:nbr100v2:*:*:*:*:*:*:*:*
The supplied data lists no other versions as affected or unaffected.
Patch Status
The sources do not mention a patch or vendor advisory. According to the CNA, Netcore was contacted early about the disclosure but "did not respond in any way." NVD lists the record's status as "Received," published 2026-09-28. There is no CISA KEV entry, so no federal required action or due date applies.
Organizations running NBR100V2 firmware 1.3.240614.030928 should treat the device as unpatched and follow the references below for updates.