Summary
CVE-2026-101000 is a critical missing-authorization vulnerability in the Netcore NBR100V2 router. The flaw resides in the ACL Handler component and allows an unauthenticated remote attacker to bypass access control and invoke a privileged configuration function. The issue carries a maximum CVSS v3.1 base score of 10.0 (Critical).
Technical details
- Root cause: the ACL rule file
/usr/share/rpcd/acl.d/unauthenticated.jsonimproperly exposes theuci.applyfunction to unauthenticated requests. - Trigger condition: manipulation of the
sectionargument passed touci.applyallows the authorization check to be bypassed, permitting the function to execute without valid credentials. - Attack vector: the vulnerability is remotely exploitable over the network with no user interaction and no privileges required.
- Impact: successful exploitation grants an unauthenticated attacker the ability to apply arbitrary configuration changes on the device, resulting in full loss of confidentiality, integrity, and availability of the router.
Affected software
- Netcore NBR100V2, firmware version 1.3.240614.030928
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No vendor-supplied patch has been published as of this writing; Netcore did not respond to disclosure attempts. Check the vendor’s support channels regularly for a firmware update addressing this issue and apply it as soon as it becomes available.
- If no patch: Restrict or disable remote/WAN-facing administrative access to the router’s management interface; place the device behind a firewall or VPN so only trusted internal hosts can reach the management RPC endpoints; monitor for unexpected configuration changes; and consider replacing or isolating affected devices where remote management cannot be disabled.

