Sceawere

Vulnerability Detail

CVE-2026-102241UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Netcore NAP930 Hard-Coded Cryptographic Key

Vulnerability Metadata

Severity
Low
Score / CVSS
2.7
Creation Date
4h ago
Vendor
Netcore
Product
NAP930
Attack Type
Use of Hard-coded Cryptographic Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in Netcore NAP930 0.1.241010.141410. This vulnerability affects unknown code of the file /lib/functions/backup_common.sh of the component Backup/Restore. This manipulation of the argument aes_pass causes use of hard-coded cryptographic key . It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.7",
  "pubDate": "2026-09-29T03:17:14.510Z",
  "pubdate": "2026-09-29T03:17:14.510Z",
  "executiveSummary": "The Netcore NAP930 firmware version 0.1.241010.141410 contains a critical security vulnerability involving the use of a hard-coded cryptographic key within the /lib/functions/backup_common.sh script. This vulnerability resides in the Backup/Restore component and specifically involves the improper handling of the 'aes_pass' argument.\nThis flaw allows a remote, unauthenticated attacker to bypass encryption mechanisms used for backup files. Because the cryptographic key is embedded directly into the source code, any attacker with access to the firmware or the ability to intercept/analyze backup processes can derive the key required to decrypt sensitive system configuration data.\nThe risk implication is high, as the vulnerability facilitates unauthorized access to potentially sensitive information, including system credentials, network configurations, and other private data stored within backups. Given that the exploit has been publicly disclosed and the vendor has remained unresponsive to disclosure attempts, the vulnerability is highly susceptible to exploitation by malicious actors scanning for vulnerable devices. There are no requirements for physical access, as the vulnerability is remotely exploitable, effectively lowering the barrier for successful system compromise.",
  "technicalDetails": "The vulnerability is localized within the shell script located at /lib/functions/backup_common.sh, which governs the execution of backup and restore operations for the Netcore NAP930. The root cause is the reliance on hard-coded cryptographic credentials for the AES encryption of backup archives, specifically linked to the handling of the 'aes_pass' parameter.\nIn the context of the /lib/functions/backup_common.sh script, the application logic incorrectly implements cryptographic operations by utilizing a static, pre-defined key rather than a dynamically generated or user-supplied key that maintains entropy. When the system initiates a backup process, the 'aes_pass' argument is processed by the script, which leverages this static key to encrypt the resulting archive. Because this key is hard-coded within the firmware, it is consistent across all instances of the NAP930 device.\nThe attack flow begins with the attacker identifying the target device, either via exposed web management interfaces or through remote administrative endpoints. An attacker can leverage the publicly disclosed exploit details to trigger a backup request, causing the device to generate an encrypted archive using the known hard-coded key. Alternatively, if an attacker obtains a backup file produced by a device, they can trivially derive the decryption key by extracting the script logic from the firmware image. Once the key is recovered, the attacker can decrypt the full contents of the backup file.\nPost-exploitation impact is severe. Backup files typically contain sensitive configuration data, including plaintext or weakly hashed administrative credentials, WPA/WPA2 pre-shared keys, and network topology details. By decrypting these files, an attacker gains sufficient information to perform lateral movement, man-in-the-middle attacks, or complete system takeover. The vulnerability does not require authentication to trigger the backup mechanism in many scenarios, and the static nature of the key renders any encryption performed by the device effectively useless against a determined adversary. The presence of the key in a shell script indicates a lack of proper secure secret management or hardware-backed keystore implementation, which is a fundamental failure in the design of the device's security architecture."
}
CVE-2026-102241: Netcore NAP930 Hard-Coded Cryptographic Key (LOW Severity, CVSS: 2.7) | Sceawere