CVE-2026-94100: Netcore NBR200V2 WAN VLAN Reconfiguration routerd wan_config_set_vlan buffer overflow
A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wanconfigsetvlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlanwanX.ports can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Devices identified as Netcore NBR200V2 running version 1.3.241127.071246 are affected in the WAN VLAN Reconfiguration component, specifically routerd's wan_config_set_vlan function.
What does an attacker need to exploit it?
The attack can be performed remotely and requires low privileges. Exploitation involves manipulating the vlan_wanX.ports argument; no user interaction is required.
Is public exploit code available?
Yes. The available information states that an exploit has been made public and could be used in attacks.
Is a vendor fix available?
No vendor response or fix is described. The vendor was contacted before disclosure but did not respond.