Junglewise Threat Intelligence

CVE-2026-94100: Netcore NBR200V2 buffer overflow in WAN VLAN configuration

CVE-2026-94100 · Severity: critical · CVSS 9.9 · Published 2026-09-21

Technologies: Netcore NBR200V2. Vendors: Netcore.

Executive brief

Netcore NBR200V2 is a network router used in enterprise deployments. A buffer overflow vulnerability in the WAN VLAN configuration function allows remote attackers to execute arbitrary code or crash the device by sending specially crafted network requests, potentially leading to complete device compromise or denial of service.

Technical details

A buffer overflow exists in the wan_config_set_vlan function within /usr/bin/routerd when processing the vlan_wanX.ports argument. The vulnerability is remotely exploitable without authentication and allows unauthenticated network-based attackers to cause memory corruption, leading to arbitrary code execution or denial of service. Public exploit code is available.

Affected products

  • Netcore NBR200V2 1.3.241127.071246

Timeline

  • 2026-09-21: disclosed
  • other: Public exploit available

References

Related threats