SECURITYCRITICALCVE-2026-101000

CVE-2026-101000: Missing Authorization in Netcore NBR100V2 ACL Handler

Netcore NBR100V2's ACL handler skips authorization on uci.apply, letting unauthenticated attackers tamper with device configuration remotely.

Dylan H.

Security Team

September 28, 2026
3 min read
CVE-2026-101000: Missing Authorization in Netcore NBR100V2 ACL Handler

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Netcore NBR100V2 1.3.240614.030928

Overview

CVE-2026-101000 affects the Netcore NBR100V2 router, firmware version 1.3.240614.030928, and involves the ACL Handler component responsible for gating which RPC calls an unauthenticated caller is allowed to make. The vulnerable file, /usr/share/rpcd/acl.d/unauthenticated.json, defines the access-control list for OpenWrt's ubus/uci RPC layer — and its uci.apply entry fails to properly restrict the section argument, allowing an unauthenticated actor to apply arbitrary UCI configuration changes to the device.

The flaw is tracked under CWE-862 (Missing Authorization), with some trackers also citing the closely related CWE-863 (Incorrect Authorization). It carries a maximum CVSS v4.0 score of 10.0 (Critical) and an equivalent CVSS 3.1 score of 10.0, reflecting network-exploitable, zero-authentication, zero-user-interaction access with high impact to confidentiality, integrity, and availability.


Technical Details

FieldValue
CVE IDCVE-2026-101000
SeverityCritical (CVSS 4.0: 10.0 / CVSS 3.1: 10.0)
WeaknessCWE-862 (Missing Authorization) / CWE-863 (Incorrect Authorization)
Vulnerable File/usr/share/rpcd/acl.d/unauthenticated.json
Functionuci.apply
ComponentACL Handler
Parametersection
AuthenticationNone required
Exploit MaturityPublic PoC available
Vendor ResponseContacted early, did not respond

How It Works

OpenWrt-based routers like the NBR100V2 use rpcd's ACL configuration files under /usr/share/rpcd/acl.d/ to define exactly which ubus/uci RPC methods an unauthenticated session is permitted to call — normally a tightly scoped allowlist covering only safe, read-only operations needed before login. On the NBR100V2, the unauthenticated.json ACL grants access to uci.apply without properly validating the section argument passed to it, so a caller with no credentials at all can invoke uci.apply against arbitrary configuration sections.

Since uci.apply is the mechanism OpenWrt uses to commit staged UCI configuration changes into the running system, an unauthenticated request that reaches this handler can modify persistent device configuration — network settings, firewall rules, or other system state — without ever authenticating. A public proof-of-concept documenting the exact request sequence has been published on GitHub, and no vendor response or patch has been reported.


Impact Assessment

Who Is At Risk

  • Any NBR100V2 unit on firmware 1.3.240614.030928 with the management/RPC interface reachable over the network
  • No vendor patch currently exists

Potential Impact

  • Unauthenticated tampering with device configuration via uci.apply, up to and including network, firewall, and routing settings
  • Full compromise of confidentiality, integrity, and availability per the CVSS 10.0 rating — an attacker who can freely rewrite configuration can disable protections, redirect traffic, or brick the device
  • A likely stepping stone to further compromise when chained with the OS command injection flaws disclosed in the same NBR200V2/NBR100V2 firmware family (see Related Reading)

Mitigation

  • Restrict network access to the router's management/RPC interface to trusted hosts only; disable WAN-side administration entirely if not required
  • Deploy network-layer monitoring for unexpected ubus/uci RPC calls or unexplained configuration drift
  • No vendor patch exists; organizations should treat NBR100V2 hardware on this firmware version as unsuitable for continued production use until Netcore ships a fix

References