Impact
The flaw is a classic buffer overflow in the vlan_load_form_uci function of Netcore’s routerd utility. By manipulating the wan_num argument, an attacker can overflow the function’s local buffer and overwrite adjacent memory. This memory corruption can be used to execute arbitrary code, leading to a full compromise of the device. The weakness corresponds to the common CWE‑119 and CWE‑120 classes of buffer overflows.
Affected Systems
The vulnerability exists in Netcore NBR200V2 routers running firmware version 1.3.241127.071246. Only the router’s routerd process is affected, but because it is a privileged service, compromising it can give an attacker administrative control over the router.
Risk and Exploitability
The score of 9.4 marks it a critical flaw. The exploit is reported to be remote, and the vulnerability has been disclosed publicly. No official patch is currently available and the vendor has not responded, so the risk remains high. Because the exploit can be triggered from outside the local network and no mitigation is offered by the vendor, administrators must assess their exposure and consider isolation or replacement of the affected device.
OpenCVE Enrichment