Junglewise Threat Intelligence

CVE-2026-94101: Netcore NBR200V2 buffer overflow in routerd VLAN handler

CVE-2026-94101 · Severity: critical · CVSS 9.9 · Published 2026-09-21

Technologies: Netcore NBR200V2. Vendors: Netcore.

Executive brief

Netcore NBR200V2 is a network router device used to manage corporate and home networks. A buffer overflow vulnerability in its routing daemon allows remote attackers to crash the device or execute arbitrary code by sending specially crafted network requests, potentially leading to network outage or complete system compromise.

Technical details

The vlan_load_form_uci function in /usr/bin/routerd contains a stack-based buffer overflow triggered by an unsanitized wan_num argument. The vulnerability is remotely exploitable without authentication and has been publicly disclosed with working exploits available.

Affected products

  • Netcore NBR200V2 1.3.241127.071246

Timeline

  • 2026-09-21: disclosed
  • other: Vendor did not respond to early disclosure notification

References

Related threats