CVE-2026-101073
Received Received - Intake

Improper Authentication in Netcore NR289-GE Router

Vulnerability report for CVE-2026-101073, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nr289-ge 1.4.5102

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101073 is an authentication bypass flaw in the Netcore NR289-GE router (firmware V1.4.5102). The vulnerability exists in the vendor-patched boa web server due to a flawed whitelist mechanism. Any URI containing '.ico' bypasses HTTP Basic authentication, allowing unauthenticated access to administrative CGI handlers.

Detection Guidance

Check if your Netcore NR289-GE router is running firmware version V1.4.5102 or earlier. Test for the vulnerability by sending a crafted request like 'POST /x.ico/location_time.cgi' to see if it bypasses authentication. Use tools like curl to verify responses from CGI handlers without credentials.

Impact Analysis

This vulnerability allows remote attackers to gain full control over the device without authentication. They can modify configurations, access sensitive information, and potentially execute arbitrary commands as root when combined with other vulnerabilities like command injection flaws.

Compliance Impact

This vulnerability allows unauthenticated remote access to administrative functions on the Netcore NR289-GE router, including configuration changes, user management, and logging. Such unauthorized access could lead to violations of data protection requirements under GDPR (e.g., unauthorized access to personal data) and HIPAA (e.g., unauthorized access to protected health information).

Mitigation Strategies

Immediately update the router firmware to the latest version if available. If no patch exists, restrict access to the router's web interface via network segmentation or firewall rules. Disable remote administration features if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101073. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart