Sceawere
Vulnerability Detail
CVE-2026-101074UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Netcore NR289-GE Buffer Overflow
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 2h ago
- Vendor
- Netcore
- Product
- NR289-GE
- Attack Type
- Stack-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-09-28T15:17:12.830Z",
"pubdate": "2026-09-28T15:17:12.830Z",
"executiveSummary": "A critical stack-based buffer overflow vulnerability exists in the Netcore NR289-GE firmware version 1.4.5102, specifically within the authentication logic of the /bin/boa web server component.\nThe vulnerability originates from improper bounds checking on the 'Username' argument processed by the 'password-check' function.\nA remote, unauthenticated attacker can exploit this weakness by submitting a maliciously crafted username string to the device, potentially leading to arbitrary code execution, denial-of-service, or complete system compromise.\nGiven that the exploit is publicly available and the vendor has remained unresponsive to disclosure attempts, the risk of active exploitation is significant.\nThe vulnerability allows for remote execution without requiring valid credentials, presenting a severe risk to the confidentiality, integrity, and availability of the affected hardware.",
"technicalDetails": "The vulnerability resides in the /bin/boa binary, which acts as the web server for the Netcore NR289-GE device. The root cause is a classic stack-based buffer overflow located within the 'password-check' function.\nDuring the authentication routine, the application retrieves the 'Username' argument from the incoming HTTP request. The code fails to perform adequate length validation before copying this user-supplied input into a fixed-length buffer allocated on the stack.\nAn attacker can exploit this by sending an oversized payload as the 'Username' parameter. The excessive data overflows the allocated stack buffer, allowing the attacker to overwrite critical data structures, including the function's return address on the stack.\nBy carefully crafting the overflow payload, an attacker can hijack the instruction pointer (EIP/RIP) when the 'password-check' function attempts to return. This enables the redirection of the execution flow to attacker-controlled shellcode or an ROP (Return Oriented Programming) chain.\nThe attack is remotely exploitable over the network, as the vulnerable component is directly exposed via the device's web management interface. Because the vulnerability is triggered during the pre-authentication phase, no valid credentials are required to execute the exploit.\nPost-exploitation, the impact is severe. Since the /bin/boa service typically runs with elevated privileges (often root) on such embedded devices, a successful overflow provides the attacker with full control over the device. This allows for persistent modification of system settings, extraction of sensitive configuration data, or the use of the device as a pivot point for further attacks on the internal network.\nThe public availability of the exploit code significantly lowers the barrier to entry for malicious actors, necessitating immediate defensive action in environments where these legacy devices remain in operation."
}