Sceawere

Vulnerability Detail

CVE-2026-101074UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Netcore NR289-GE Buffer Overflow

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
2h ago
Vendor
Netcore
Product
NR289-GE
Attack Type
Stack-based Buffer Overflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-28T15:17:12.830Z",
  "pubdate": "2026-09-28T15:17:12.830Z",
  "executiveSummary": "A critical stack-based buffer overflow vulnerability exists in the Netcore NR289-GE firmware version 1.4.5102, specifically within the authentication logic of the /bin/boa web server component.\nThe vulnerability originates from improper bounds checking on the 'Username' argument processed by the 'password-check' function.\nA remote, unauthenticated attacker can exploit this weakness by submitting a maliciously crafted username string to the device, potentially leading to arbitrary code execution, denial-of-service, or complete system compromise.\nGiven that the exploit is publicly available and the vendor has remained unresponsive to disclosure attempts, the risk of active exploitation is significant.\nThe vulnerability allows for remote execution without requiring valid credentials, presenting a severe risk to the confidentiality, integrity, and availability of the affected hardware.",
  "technicalDetails": "The vulnerability resides in the /bin/boa binary, which acts as the web server for the Netcore NR289-GE device. The root cause is a classic stack-based buffer overflow located within the 'password-check' function.\nDuring the authentication routine, the application retrieves the 'Username' argument from the incoming HTTP request. The code fails to perform adequate length validation before copying this user-supplied input into a fixed-length buffer allocated on the stack.\nAn attacker can exploit this by sending an oversized payload as the 'Username' parameter. The excessive data overflows the allocated stack buffer, allowing the attacker to overwrite critical data structures, including the function's return address on the stack.\nBy carefully crafting the overflow payload, an attacker can hijack the instruction pointer (EIP/RIP) when the 'password-check' function attempts to return. This enables the redirection of the execution flow to attacker-controlled shellcode or an ROP (Return Oriented Programming) chain.\nThe attack is remotely exploitable over the network, as the vulnerable component is directly exposed via the device's web management interface. Because the vulnerability is triggered during the pre-authentication phase, no valid credentials are required to execute the exploit.\nPost-exploitation, the impact is severe. Since the /bin/boa service typically runs with elevated privileges (often root) on such embedded devices, a successful overflow provides the attacker with full control over the device. This allows for persistent modification of system settings, extraction of sensitive configuration data, or the use of the device as a pivot point for further attacks on the internal network.\nThe public availability of the exploit code significantly lowers the barrier to entry for malicious actors, necessitating immediate defensive action in environments where these legacy devices remain in operation."
}
CVE-2026-101074: Netcore NR289-GE Buffer Overflow (CRITICAL Severity, CVSS: 9.8) | Sceawere