CVE-2026-101077
Received Received - Intake

Authentication Bypass in Netcore NR289-GE Router

Vulnerability report for CVE-2026-101077, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nr289-ge 1.4.5102

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101077 is a missing authentication flaw in Netcore NR289-GE router firmware version 1.4.5102. The vulnerability exists in the boa web server's process_request function, allowing remote attackers to write arbitrary files without authentication by sending crafted POST requests to specific paths like /x.ico/firmware_upgrade or /x.ico/para_recover. The attack is stealthy as the server always responds with a 404 error regardless of success.

Detection Guidance

Check for unauthenticated POST requests to paths containing 'update', 'upgrade', or 'para_recover' on the Netcore NR289-GE router. Monitor for unexpected file writes to /tmp/boa_temp.update or /tmp/boa_temp.para. Inspect network traffic for POST requests with 404 responses despite successful file operations.

Impact Analysis

This vulnerability allows remote attackers to write arbitrary files to the router's /tmp directory without authentication. Potential impacts include denial of service by corrupting staged firmware files, restoring arbitrary configurations that may expose web credentials, and enabling further attacks when combined with other flaws like authentication bypass vulnerabilities.

Compliance Impact

This vulnerability allows unauthenticated remote attackers to write arbitrary files to the router, which could lead to exposure of sensitive data such as web credentials or configuration files. This may violate GDPR requirements for data protection and HIPAA requirements for safeguarding protected health information if such data is stored or transmitted through the affected device.

Mitigation Strategies

Isolate the affected router from external networks. Disable the boa web server if possible. Apply firmware updates if available. Block suspicious POST requests to vulnerable paths at the network perimeter. Monitor for signs of exploitation such as unexpected file writes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101077. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart