Sceawere
Vulnerability Detail
CVE-2026-101072UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Netcore NR289-GE OS Command Injection
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 3h ago
- Vendor
- Netcore
- Product
- NR289-GE
- Attack Type
- OS Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-09-28T14:17:13.973Z",
"pubdate": "2026-09-28T14:17:13.973Z",
"executiveSummary": "A critical OS command injection vulnerability exists within the Netcore NR289-GE router, specifically located in the CGI handler responsible for managing network configurations. The vulnerability resides in the /ap_ip.cgi script, where inadequate sanitization of the 'ip' parameter allows for the execution of arbitrary system-level commands.\nThis flaw enables unauthenticated remote attackers to achieve remote code execution (RCE) on the device. By injecting malicious shell metacharacters into the vulnerable argument, an adversary can manipulate the underlying system process, leading to a complete compromise of the router's operating environment. The risk is significantly elevated due to the public availability of exploit code and the vendor's lack of responsiveness, leaving deployments exposed to automated and targeted attacks.\nThe potential impact includes unauthorized access to internal network traffic, device hijacking, and the capability to use the compromised hardware as a pivot point for further network infiltration. Given that the attack can be launched remotely without prior authentication, this vulnerability represents a severe threat to operational security.",
"technicalDetails": "The vulnerability is localized within the component /ap_ip.cgi of the Netcore NR289-GE firmware version 1.4.5102. The root cause is an improper neutralization of special elements used in an OS command, commonly referred to as CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection).\nDuring the processing of HTTP GET or POST requests directed at /ap_ip.cgi, the application retrieves the 'ip' argument directly from the user-supplied input. This input is then passed to a system-level function, likely a C-based system() call or an equivalent execution wrapper, without sufficient validation, filtering, or escaping of shell metacharacters such as semicolons, pipes, or backticks.\nThe attack flow proceeds as follows: An attacker sends a crafted HTTP request to the /ap_ip.cgi endpoint. The 'ip' parameter is injected with a malicious payload, such as '127.0.0.1; [malicious_command]'. Upon reaching the vulnerable function, the CGI handler constructs a command string concatenating the user input directly into a command execution buffer. Because the application fails to sanitize the 'ip' variable, the shell interpreter interprets the injected characters as command separators, executing the attacker's payload with the privileges of the web server or the system's root account.\nDue to the nature of the CGI handler, this vulnerability is exploitable remotely over the network. There are no authentication requirements specified, meaning an attacker can initiate this injection sequence from any network segment that can communicate with the target device's web interface. The payload behavior is limited only by the system's shell capabilities; common post-exploitation activities include installing persistent backdoors, exfiltrating configuration files, or launching denial-of-service attacks against internal network resources.\nThe lack of memory protections and robust input validation in the firmware's CGI component exacerbates the exploitability. Because the vendor has provided no response or patch, the vulnerability persists in the stated firmware version, allowing for simple, script-based exploitation that bypasses standard access control mechanisms."
}