CVE-2026-101072
Deferred Deferred - Pending Action

OS Command Injection in Netcore NR289-GE Router

Vulnerability report for CVE-2026-101072, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nr289-ge 1.4.5102

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated OS command injection flaw in the Netcore NR289-GE router running firmware version V1.4.5102. It exists in the ap_ip.cgi endpoint due to improper validation of the ip parameter, which is copied into a shell command template and executed via the system() function without proper sanitization.

Detection Guidance

To detect this vulnerability, check if your Netcore NR289-GE router is running firmware version V1.4.5102. Scan for requests to /<anything>.ico/ap_ip.cgi with crafted parameters like mac=AA:BB:CC:DD:EE:FF and ip=";echo ok>/tmp/p;#. Use network monitoring tools to identify suspicious POST requests targeting this endpoint.

  • Check router firmware version via admin panel or SSH. Look for unusual file writes in /tmp/ or configuration changes.
Impact Analysis

An attacker can remotely execute arbitrary commands as root on the affected device without authentication. This allows full compromise of the router, enabling file writes, configuration changes, or staging further attacks. The exploit is publicly available and can be launched remotely.

Mitigation Strategies

Immediately update the router firmware to a patched version if available. If no patch exists, isolate the device from the internet or untrusted networks. Disable remote administration features and block external access to the router's web interface.

  • Monitor for signs of exploitation like unexpected file writes in /tmp/ or unauthorized configuration changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101072. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart