Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-94101: Netcore NBR200V2 router allows remote code execution
CVE-2026-94101 · published 8 days ago
Summary
The router's software component that handles VLAN settings can be tricked into overwriting memory when a specially crafted WAN number is sent. An attacker on the network could exploit this to run their own code on the device. Update the router firmware or apply the vendor's patch as soon as it is available.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| netcore | nbr200v2 | 1.3.241127.071246 |
Original advisory text
Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow
A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
8.6
High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-120Classic Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published21 Sep 2026
Updated27 Sep 2026
First seen21 Sep 2026
Track software like this
Free during beta