CVE-2026-101075
Received Received - Intake

OS Command Injection in Netcore NR289-GE Router

Vulnerability report for CVE-2026-101075, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nr289-ge 1.4.5102

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated command injection vulnerability in the Netcore NR289-GE router (firmware V1.4.5102). The flaw exists in the location_time.cgi endpoint, which can be accessed without authentication via a path traversal bypass. The mac parameter is passed unsanitized into a shell command executed by system(), allowing attackers to inject arbitrary commands.

Detection Guidance

Check if the Netcore NR289-GE router is running firmware version V1.4.5102 or similar. Test the vulnerable endpoint by sending a crafted request to /<anything>.ico/location_time.cgi with a mac parameter containing command injection payloads. Monitor for unexpected command execution or file writes in /web/images/

Example commands: curl -v 'http://<router-ip>/test.ico/location_time.cgi?mac=;id>' to test for command injection. Check logs for suspicious CGI access patterns or unauthorized file modifications.

Impact Analysis

Attackers can execute commands with root privileges, leading to full device compromise. This includes modifying configurations, establishing persistence, intercepting traffic, and attacking managed access points. A proof-of-concept shows command execution by writing to a web-accessible file, and a reverse shell can be established.

Compliance Impact

This vulnerability allows unauthenticated remote command injection with root privileges, enabling full device compromise. Such unauthorized access could lead to unauthorized data access, modification, or exfiltration, violating GDPR data protection principles and HIPAA security requirements for safeguarding sensitive information.

Mitigation Strategies

Isolate the affected router from the network immediately. Disable remote access to CGI endpoints if possible. Update the firmware to the latest version if a patch is available. Block external access to /<anything>.ico/location_time.cgi and similar paths via firewall rules.

Monitor for signs of compromise such as unexpected file writes or unauthorized command execution. Consider replacing the device if no patch is available, as the vendor did not respond to disclosure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101075. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart