A remotely reachable buffer overflow in the Netcore NBR200V2 router's WAN VLAN reconfiguration handler carries a CVSS 3.1 score of 9.9 and already has a publicly available exploit, with the vendor silent on disclosure.
What Is It
CVE-2026-94100 is a buffer overflow (CWE-119, CWE-120) in Netcore NBR200V2 firmware version 1.3.241127.071246. The flaw sits in the wan_config_set_vlan function of /usr/bin/routerd, part of the WAN VLAN Reconfiguration component. Manipulating the vlan_wanX.ports argument triggers the overflow. The attack can be performed remotely.
VulDB, the assigning CNA, rates it CVSS 3.1 9.9 CRITICAL (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) and CVSS 4.0 8.6 HIGH. The record is currently in "Received" status at NVD.
Why It Matters
The CVSS 3.1 vector combines network attack vector, low attack complexity, and no user interaction; with only low privileges required. Scope is marked Changed, and confidentiality, integrity, and availability impacts are all High, which is what drives the 9.9. The CVSS 4.0 rating is lower at 8.6 HIGH; the supplied data gives only that score, not the underlying 4.0 vector, so the per-metric breakdown behind the difference cannot be confirmed from the source material.
Exploit maturity is rated PROOF_OF_CONCEPT in the VulDB CTI data, and the NVD description states plainly that the exploit has been made public and could be used for attacks. This is not a theoretical finding.
The CVE does not appear in the CISA Known Exploited Vulnerabilities catalog, so active exploitation is not confirmed by KEV at this time.
What's Vulnerable
- Vendor: Netcore
- Product: NBR200V2
- Version: 1.3.241127.071246 (affected)
- Component: WAN VLAN Reconfiguration
- Binary/function:
/usr/bin/routerd→wan_config_set_vlan - CPE:
cpe:2.3:a:netcore:nbr200v2:*:*:*:*:*:*:*:*
Patch Status
No patch is referenced in the supplied data. Per the NVD record, the vendor was contacted early about this disclosure but did not respond in any way. No vendor advisory, fixed version, or required remediation action is present in the source material.
Sources
- NVD, CVE-2026-94100 record (source: [email protected]): https://nvd.nist.gov/vuln/detail/CVE-2026-94100
- CISA, Known Exploited Vulnerabilities Catalog (no entry for CVE-2026-94100): https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- VulDB, CVE entry: https://vuldb.com/cve/CVE-2026-94100
- VulDB, Vulnerability detail: https://vuldb.com/vuln/408029
- VulDB, CTI data (exploit maturity: PROOF_OF_CONCEPT): https://vuldb.com/vuln/408029/cti
- VulDB, Submission record: https://vuldb.com/submit/892994
- Researcher write-up (Notion): https://app.notion.com/p/Netcore-NBR200V2-Vul-8-39f797159f158003ad3eff2fd36342b6