CVE-2026-101074
Received Received - Intake

Stack-Based Buffer Overflow in Netcore NR289-GE Authentication

Vulnerability report for CVE-2026-101074, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nr289-ge 1.4.5102

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer overflow in the Netcore NR289-GE router's boa web server. The vulnerability occurs in the password-check function which uses unsafe strcpy operations to copy the username from an HTTP Authorization header into two 64-byte stack buffers. A username of 96 bytes or more can overwrite the return address and other registers, allowing control of the program counter. The flaw is exploitable without authentication and can lead to remote code execution with root privileges.

Detection Guidance

To detect this vulnerability, monitor for crashes in the boa web server process on Netcore NR289-GE devices running firmware V1.4.5102. Check for repeated restarts of the boa process, which may indicate a crash loop due to the stack overflow. Use network scanning tools to identify devices exposing the HTTP Basic authentication port (typically 80).

  • Check running processes: ps aux | grep boa
  • Monitor logs for crashes: tail -f /var/log/messages | grep -i 'boa'
  • Scan for open HTTP ports: nmap -p 80 <target_IP>
Impact Analysis

An attacker could remotely crash the router's web server via a denial-of-service or execute arbitrary code with root privileges. This could allow full control of the device, interception of network traffic, or use of the router as a pivot point for further attacks on the local network.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) and HIPAA (health information security). A successful exploit could allow attackers to gain root privileges, potentially exposing personal or protected health information.

Mitigation Strategies

Immediately isolate affected Netcore NR289-GE devices from your network to prevent exploitation. Disable the boa web server if possible, as it is the vulnerable component. Contact Netcore for a firmware update or patch. If no patch is available, consider replacing the device with a supported model.

  • Block external access to port 80 on the device using firewall rules.
  • Disable HTTP Basic authentication if not required for operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101074. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart