Sceawere

Vulnerability Detail

CVE-2026-101075UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Netcore NR289-GE OS Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
2h ago
Vendor
Netcore
Product
NR289-GE
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-09-28T15:17:13.043Z",
  "pubdate": "2026-09-28T15:17:13.043Z",
  "executiveSummary": "A critical OS command injection vulnerability exists within the Location Time Handler component of Netcore NR289-GE version 1.4.5102. The vulnerability stems from improper sanitization of the 'mac' parameter within the '/location_time.cgi' file, allowing unauthenticated remote attackers to execute arbitrary system-level commands with the privileges of the web server.\nThis flaw facilitates complete system compromise, enabling adversaries to modify system configurations, exfiltrate sensitive data, or integrate the affected device into a botnet. Given that the exploit code has been publicly disclosed and the vendor has remained unresponsive, the risk of exploitation is significantly elevated. The attack can be executed remotely without prior authentication, posing a severe threat to the integrity and confidentiality of the device's operating environment.",
  "technicalDetails": "The vulnerability is classified as an OS command injection, occurring within the 'system' function call in the '/location_time.cgi' script. The root cause is the insecure handling of user-supplied input provided through the 'mac' argument. The application fails to validate or sanitize the input before passing it directly into a system shell execution context.\nThe attack flow begins when an attacker sends a specially crafted HTTP request to the '/location_time.cgi' endpoint. By appending shell metacharacters—such as semicolons (;), pipes (|), or backticks (`)—to the 'mac' parameter, an attacker can break out of the intended command context. For instance, an input string structured as 'mac=[valid_mac];[malicious_command]' forces the underlying operating system to interpret the second part of the string as a new, distinct command line operation.\nSince the affected component, the Location Time Handler, executes with elevated system privileges, the injected commands are run with the same level of access. This allows for unauthorized execution of arbitrary binaries or shell scripts. The lack of input validation mechanism allows for full exploitation of the shell environment, granting the remote attacker the ability to navigate the filesystem, modify binary files, or install persistence mechanisms.\nThe vulnerability is network-exposed, as the web interface is typically accessible over the local area network or WAN, depending on device configuration. There are no authentication requirements specified, implying the vulnerability can be triggered directly by an external actor targeting the CGI script. Post-exploitation, the attacker gains full control over the underlying Linux-based firmware environment, enabling a wide range of secondary attacks including data exfiltration, service disruption, and lateral movement within the network segment where the device is deployed. Because the vendor has provided no patch, the firmware remains permanently exposed to this vector."
}
CVE-2026-101075: Netcore NR289-GE OS Command Injection (CRITICAL Severity, CVSS: 10.0) | Sceawere