Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-101000: Netcore NBR100V2 allows remote actions without permission

CVE-2026-101000 · published 12 days ago
Summary

The Netcore NBR100V2 device can be triggered over the network to perform actions without checking whether the user is authorized. This occurs because a specific settings file does not correctly verify who is making the request. Apply the latest security update from Netcore or restrict network access to the device until a fix is installed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
netcore nbr100v2 1.3.240614.030928
Original advisory text
Netcore NBR100V2 ACL unauthenticated.json uci.apply authorization
A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-862Missing Authorization
CWE-863Incorrect Authorization
Timeline
Published28 Sep 2026
Updated7 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-101000 · MITRE
Track software like this
Free during beta