Impact
A buffer overflow is present in the wan_config_set_vlan function of the /usr/bin/routerd daemon, triggered by manipulating the vlan_wanX.ports argument. This flaw, a CWE-119 and CWE-120 type buffer overflow, can allow an attacker to corrupt memory and potentially execute arbitrary code with the privileges of the routerd process.
Affected Systems
The vulnerability affects Netcore NBR200V2 model firmware version 1.3.241127.071246. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS score of 9.4 marks this issue as critical. Although the EPSS score is not publicly available and the vulnerability is not yet listed in CISA KEV, the exploit is publicly available and can be launched from remote locations. The combination of a high severity rating, remote attack vector, and public exploit availability results in a high likelihood of exploitation and significant risk to affected systems.
OpenCVE Enrichment