Executive brief
Netcore NBR200V2 is a network router used in enterprise deployments. A buffer overflow vulnerability in the WAN VLAN configuration function allows remote attackers to execute arbitrary code or crash the device by sending specially crafted network requests, potentially leading to complete device compromise or denial of service.
Technical details
A buffer overflow exists in the wan_config_set_vlan function within /usr/bin/routerd when processing the vlan_wanX.ports argument. The vulnerability is remotely exploitable without authentication and allows unauthenticated network-based attackers to cause memory corruption, leading to arbitrary code execution or denial of service. Public exploit code is available.
Affected products
- Netcore NBR200V2 1.3.241127.071246
Timeline
- 2026-09-21: disclosed
- other: Public exploit available