<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:netcore:nbr100v2:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3anetcorenbr100v2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 08:49:12 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3anetcorenbr100v2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Missing Authorization Vulnerability in Netcore NBR100V2</title><link>https://feed.craftedsignal.io/briefs/2026-09-netcore-acl-bypass/</link><pubDate>Mon, 28 Sep 2026 08:49:12 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-netcore-acl-bypass/</guid><description>An unauthenticated remote authorization bypass vulnerability exists in the Netcore NBR100V2 router, allowing attackers to manipulate system configurations via the ACL Handler component.</description><content:encoded><![CDATA[<p>A critical missing authorization vulnerability has been identified in the Netcore NBR100V2 router (firmware version 1.3.240614.030928). The vulnerability exists within the ACL Handler component, specifically impacting the 'uci.apply' function. This flaw is rooted in an improperly defined access control list (ACL) within the '/usr/share/rpcd/acl.d/unauthenticated.json' configuration file.</p>
<p>The vulnerability allows remote, unauthenticated attackers to manipulate the 'section' argument, potentially resulting in unauthorized system configuration changes. Given that the exploit has been publicly disclosed and the vendor has not provided a response or a patch, systems running this specific firmware version are at significant risk of unauthorized administrative control. Defenders should prioritize identifying and isolating these devices from external networks.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated remote attackers to bypass authorization controls, which can lead to unauthorized modification of router configurations. Given the base CVSS score of 10.0, the potential for total system compromise is high. This affects enterprise and home-office deployments relying on the Netcore NBR100V2 router for network security and traffic management.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately restrict access to the management interface of Netcore NBR100V2 routers to trusted internal IP ranges or VPNs only.</li>
<li>Disable remote administrative access on all internet-facing Netcore NBR100V2 devices.</li>
<li>Monitor network traffic logs for unusual HTTP POST requests directed at internal ACL handling endpoints or attempts to interact with the 'uci.apply' function.</li>
<li>As no vendor patch is currently available, evaluate replacing the affected hardware or isolating it behind a hardened perimeter gateway.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>network-security</category><category>acl-bypass</category></item></channel></rss>