Sceawere
Vulnerability Detail
CVE-2026-101076UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Netcore NR289-GE OS Command Injection
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 4h ago
- Vendor
- Netcore
- Product
- NR289-GE
- Attack Type
- OS Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-09-28T16:17:11.947Z",
"pubdate": "2026-09-28T16:17:11.947Z",
"executiveSummary": "A critical OS command injection vulnerability has been identified in the Netcore NR289-GE router, specifically within the firmware version 1.4.5102.\nThe vulnerability resides in the CGI handler responsible for NTP server configuration, allowing unauthenticated remote attackers to execute arbitrary system commands with elevated privileges.\nThe flaw stems from improper sanitization of the 'ntp_ip' argument during the execution of system calls within the /set_ntp_server_ip.cgi file.\nThis vulnerability poses a severe security risk, as successful exploitation permits full device compromise, potentially facilitating lateral movement within the network, data exfiltration, or the installation of persistent malicious payloads.\nGiven that the vendor has failed to provide a response or a corrective patch, the device remains in a perpetually vulnerable state.\nPublicly available exploit code increases the likelihood of opportunistic exploitation by threat actors targeting exposed network infrastructure.",
"technicalDetails": "The vulnerability is classified as an OS command injection flaw located within the CGI management interface of the Netcore NR289-GE device, specifically affecting version 1.4.5102.\nThe root cause is the insecure handling of user-supplied input provided to the 'ntp_ip' parameter within the '/set_ntp_server_ip.cgi' script. The application passes this input directly to a system-level function without adequate validation, filtering, or sanitization of shell metacharacters.\nAn attacker can exploit this by crafting a malicious HTTP request targeting the aforementioned CGI endpoint. By appending command separators—such as semicolons, pipes, or backticks—to the 'ntp_ip' argument, an attacker can escape the intended function scope and inject arbitrary shell commands.\nThe attack flow follows a predictable sequence: First, the attacker sends a crafted HTTP POST or GET request to the target device's web management interface, targeting '/set_ntp_server_ip.cgi'. Second, the backend CGI handler parses the request and extracts the 'ntp_ip' argument. Third, because the underlying implementation fails to sanitize this string before passing it to the OS shell for execution (likely via functions like system() or popen()), the injected command is executed with the privileges of the web service process, which typically possesses root or administrative rights.\nThis remote code execution (RCE) capability is particularly dangerous because it does not require prior authentication, allowing any remote user with network access to the device management interface to trigger the exploit.\nPost-exploitation, the attacker gains full control over the router's operating environment. This allows for the modification of configuration settings, redirection of traffic (man-in-the-middle attacks), exfiltration of stored credentials, or the deployment of a backdoor to maintain persistent unauthorized access. Given that the affected component is a gateway device, compromised hardware acts as an ideal pivot point for further intrusions into the internal local area network (LAN), circumventing perimeter security controls."
}