Skip to content
Threat Feed
high advisory

Remote Authentication Bypass in Netcore POWER13 Routers

A publicly disclosed vulnerability in Netcore POWER13 (version 2.0.240730.162638) allows remote attackers to manipulate the routerd.passwd_set function via /ubus, resulting in weak password recovery.

CVE search metadata

CVE search record: CVE-2026-101188. Severity: high. CVSS: 8.3. KEV: no. Product: POWER13 (2.0.240730.162638). Brief: Remote Authentication Bypass in Netcore POWER13 Routers. Brief link: https://feed.craftedsignal.io/briefs/2026-09-netcore-power13-vulnerability/

A security vulnerability has been identified in Netcore POWER13 routers, specifically within version 2.0.240730.162638. The flaw resides in the 'routerd.passwd_set' function, accessible through the '/ubus' path. An unauthenticated remote attacker can exploit this endpoint to manipulate password recovery mechanisms, effectively forcing a weak password or bypassing existing security controls.

This vulnerability (CVE-2026-101188) is currently publicly disclosed, and exploitation material is available. Despite attempts to contact the vendor, Netcore has not provided a response or a patch to address this issue. This poses a significant risk to organizational infrastructure relying on these routers for remote management, as it allows for unauthorized access to administrative functions. Defenders should assume that this vulnerability is accessible from the WAN interface if the router is not properly segmented.

Impact

Successful exploitation of this vulnerability enables unauthorized actors to reset or weaken administrative credentials on affected Netcore POWER13 devices. This provides remote attackers with administrative control over the router, potentially allowing for traffic interception, persistent access via unauthorized VPN or SSH configurations, and lateral movement into the protected internal network. Organizations using these devices in internet-facing configurations are at the highest risk of total device compromise.

Recommendation

  • Immediately isolate all Netcore POWER13 devices from the public internet if they are not strictly required to be exposed.
  • Implement strict firewall rules to restrict access to the /ubus interface to known management IPs only, until the vendor provides a remediation or patch for CVE-2026-101188.
  • Monitor network traffic logs for HTTP requests directed at the /ubus path, specifically focusing on POST or call requests containing parameters associated with 'routerd.passwd_set'.
  • Given the lack of a vendor response, evaluate the necessity of these devices within the environment and consider a migration to alternative hardware that receives active security support.

Immediate actions

Restrict access to /ubus interface on affected Netcore routers via firewall

IT Operations 24h

Mitigations

Remove Netcore POWER13 routers from internet-facing positions

immediate IT Operations

CVE-2026-101188