Sceawere

Vulnerability Detail

CVE-2026-101073UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Netcore NR289-GE Improper Authentication

Vulnerability Metadata

Severity
High
Score / CVSS
8.3
Creation Date
2h ago
Vendor
Netcore
Product
NR289-GE
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.3",
  "pubDate": "2026-09-28T15:17:12.603Z",
  "pubdate": "2026-09-28T15:17:12.603Z",
  "executiveSummary": "A critical security vulnerability has been identified in the Netcore NR289-GE router, specifically within the CGI Dispatcher component.\nThe flaw stems from an improper authentication implementation in the /bin/boa binary, which manages Common Gateway Interface (CGI) requests.\nThe vulnerability allows remote, unauthenticated attackers to bypass security controls, potentially gaining unauthorized access to administrative functions or system configurations.\nGiven that the exploit is publicly available, the risk to impacted devices is high, particularly as the vendor has remained unresponsive to disclosure attempts.\nExploitation does not require prior authentication, and the remote nature of the attack allows for widespread targeting of exposed devices.\nUsers of the affected firmware version 1.4.5102 are at significant risk of compromise, as the lack of authentication mechanisms permits unauthorized actors to interact with the device's internal management interfaces.",
  "technicalDetails": "The vulnerability resides within the /bin/boa binary on the Netcore NR289-GE running firmware version 1.4.5102. The boa web server serves as the CGI Dispatcher for the device's web-based management interface. The root cause of the issue is an improper authentication check during the processing of CGI requests handled by the binary.\nThe CGI Dispatcher is responsible for mapping incoming HTTP requests to specific backend functions. Due to an oversight in the authentication logic, the binary fails to adequately validate the session state or authorization tokens before executing sensitive functions. This allows an attacker to invoke administrative routines without satisfying the required authentication handshake.\nThe attack flow begins with a remote actor sending a crafted HTTP request to the target device. Because the authentication logic within the /bin/boa process is improperly implemented, the CGI Dispatcher treats these malicious, unauthenticated requests as legitimate administrative calls. The attacker can target specific, yet currently undefined, functions that reside within the binary to manipulate device settings, bypass access control lists, or potentially execute arbitrary code depending on the function's scope.\nBecause the /bin/boa process typically runs with elevated system privileges to perform necessary configuration changes on the router, an unauthorized invocation of these functions leads to a complete compromise of the device's management integrity. The exploitation does not require the attacker to possess a valid login session or local network access, as the device is susceptible via its WAN-side interface if it is exposed to the public internet.\nPost-exploitation impact includes, but is not limited to, the modification of network routing tables, DNS settings interception, credential exfiltration, or the establishment of persistent backdoors within the router firmware. As the exploit is publicly disclosed, the barrier to entry for attackers is minimal, requiring only the ability to reach the device's web management interface over HTTP. The vulnerability persists because the underlying logic in the /bin/boa binary fails to enforce strict access control, effectively nullifying the protection provided by the device's login page."
}
CVE-2026-101073: Netcore NR289-GE Improper Authentication (HIGH Severity, CVSS: 8.3) | Sceawere