External risk intelligence

Netcore NBR100V2 Missing Authorization Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-101000

The affected product is a router, which is typically deployed as an internet-facing edge gateway. The vulnerability exists within an unauthenticated ACL handler, making it directly reachable and exposed to the public internet as part of the device's normal network-facing role.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Netcore routers, specifically within the ACL Handler component. This flaw allows for remote exploitation due to missing authorization, and the exploit has been publicly disclosed, increasing the risk of potential misuse. The vendor has not responded to inquiries regarding this issue.

  • Unauthenticated remote access to router functions.
  • Routers are critical internet-facing gateways.
  • Confirm router exposure and investigate potential impact.

Attack Path

How an attacker could exploit the issue

An attacker can remotely access a vulnerable Netcore router and manipulate its configuration by exploiting a missing authorization flaw in the ACL handler. This manipulation targets the `uci.apply` function within the router's administration interface, potentially leading to a complete compromise of the device.

  • No authentication required for attack.
  • Manipulation of configuration arguments.
  • Complete device compromise risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to manipulate device configurations on the affected router when it's accessible remotely. This could potentially impact the router's normal network operations. No specific user data or PII is indicated as being at risk.

  • Router configurations at risk.
  • Remotely initiated manipulation.
  • Disruption of network services.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Netcore NBR100V2 router's ACL handler is critical, with remote, unauthenticated exploit potential and public disclosure. Given the router's typical role as an internet-facing edge device, infrastructure and network security teams must prioritize identifying all affected devices. Once located, assess their business criticality and internet reachability to plan remediation, which may involve vendor coordination due to the vendor's non-responsiveness.

  • Infrastructure or Network Security teams own the issue.
  • Verify internet-facing router exposure and criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Netcore NBR100V2 router?

The Netcore NBR100V2 is a networking device typically deployed as an edge gateway. It manages traffic between a local network and the internet, serving as the first line of connection for connected devices.

What does CWE-862 mean for CVE-2026-101000?

CWE-862 is a weakness class defined as Missing Authorization. In this CVE, it means the router's software fails to check if a user is allowed to perform a specific action, allowing unauthorized commands to be executed.

How is this vulnerability triggered?

The flaw is triggered by manipulating the argument section within the uci.apply function. Because the vulnerability exists in an unauthenticated component, local network access is not required to trigger the bug; it can be initiated remotely.

Why should I be concerned about my Netcore NBR100V2?

According to Halo Surface Signal, this router is typically used as an internet-facing edge gateway. Because the vulnerability lies in an unauthenticated handler, it is directly reachable from the public internet, posing a high risk for unauthorized remote access.

What should I do if I use this router?

First, identify if any of your routers are running the affected Netcore NBR100V2 software. Assess their business criticality and whether they are exposed to the internet. Given the vendor's current lack of response, consider restricting administrative access to internal-only interfaces.

References