CVE-2026-94101: Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow
A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlanloadformuci of the file /usr/bin/routerd. The manipulation of the argument wannum leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
The CVSS vector indicates low privileges are required (PR:L). The attack can be initiated remotely and does not require user interaction.
Which deployed version is identified as affected?
The reported affected version is Netcore NBR200V2 1.3.241127.071246. The provided data does not establish whether other versions are affected.
Is public exploitation a concern?
Yes. The exploit has been publicly disclosed and may be used. The vendor was contacted early but did not provide a response.