PT-2026-99546 · Netcore · Nbr100V2

·

CVE-2026-101000

·

Published

2026-09-27

·

Updated

2026-10-01

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netcore NBR100V2 version 1.3.240614.030928
Description An authorization bypass exists in the ACL Handler component within the file /usr/share/rpcd/acl.d/unauthenticated.json. A remote attacker can manipulate the section argument of the uci.apply() function to perform unauthorized actions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the uci.apply() function within the ACL Handler component.

Exploit

Incorrect Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101000

Affected Products

Nbr100V2