{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anetcorepower13/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:netcore:power13:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-101188"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["POWER13 (2.0.240730.162638)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Netcore"],"content_html":"\u003cp\u003eA security vulnerability has been identified in Netcore POWER13 routers, specifically within version 2.0.240730.162638. The flaw resides in the 'routerd.passwd_set' function, accessible through the '/ubus' path. An unauthenticated remote attacker can exploit this endpoint to manipulate password recovery mechanisms, effectively forcing a weak password or bypassing existing security controls.\u003c/p\u003e\n\u003cp\u003eThis vulnerability (CVE-2026-101188) is currently publicly disclosed, and exploitation material is available. Despite attempts to contact the vendor, Netcore has not provided a response or a patch to address this issue. This poses a significant risk to organizational infrastructure relying on these routers for remote management, as it allows for unauthorized access to administrative functions. Defenders should assume that this vulnerability is accessible from the WAN interface if the router is not properly segmented.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability enables unauthorized actors to reset or weaken administrative credentials on affected Netcore POWER13 devices. This provides remote attackers with administrative control over the router, potentially allowing for traffic interception, persistent access via unauthorized VPN or SSH configurations, and lateral movement into the protected internal network. Organizations using these devices in internet-facing configurations are at the highest risk of total device compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately isolate all Netcore POWER13 devices from the public internet if they are not strictly required to be exposed.\u003c/li\u003e\n\u003cli\u003eImplement strict firewall rules to restrict access to the /ubus interface to known management IPs only, until the vendor provides a remediation or patch for CVE-2026-101188.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic logs for HTTP requests directed at the /ubus path, specifically focusing on POST or call requests containing parameters associated with 'routerd.passwd_set'.\u003c/li\u003e\n\u003cli\u003eGiven the lack of a vendor response, evaluate the necessity of these devices within the environment and consider a migration to alternative hardware that receives active security support.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T22:23:06Z","date_published":"2026-09-28T22:23:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-netcore-power13-vulnerability/","summary":"A publicly disclosed vulnerability in Netcore POWER13 (version 2.0.240730.162638) allows remote attackers to manipulate the routerd.passwd_set function via /ubus, resulting in weak password recovery.","title":"Remote Authentication Bypass in Netcore POWER13 Routers","url":"https://feed.craftedsignal.io/briefs/2026-09-netcore-power13-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:netcore:power13:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}