CVE-2026-102241
Received Received - Intake

Hard-Coded Cryptographic Key in Netcore NAP930 Firmware

Vulnerability report for CVE-2026-102241, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A vulnerability was determined in Netcore NAP930 0.1.241010.141410. This vulnerability affects unknown code of the file /lib/functions/backup_common.sh of the component Backup/Restore. This manipulation of the argument aes_pass causes use of hard-coded cryptographic key . It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nap930 From 0.1.241010.141410 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-320 Key Management Errors
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-102241 is a vulnerability in Netcore NAP930 firmware version 0.1.241010.141410 where a hard-coded AES encryption key ('netcore123') is used for securing configuration backups. This key is identical across all devices and embedded in the firmware, making it easily extractable.

Detection Guidance

Check if your Netcore NAP930 device is running firmware version V0.1.241010.141410. Inspect backup files from the /cgi-bin/backup?action=backup endpoint for decryption using the hard-coded key 'netcore123'. Verify if sensitive data like Wi-Fi credentials or passwords are exposed after decryption.

Impact Analysis

An attacker can exploit this by downloading an encrypted backup file from the device's authenticated endpoint and decrypting it offline using the hard-coded key. This reveals sensitive information such as Wi-Fi credentials, DDNS/VPN account passwords, network topology, and management settings, allowing unauthorized network access and potential account takeovers.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and encryption standards such as GDPR and HIPAA, as it exposes sensitive data due to inadequate cryptographic key management and insecure backup mechanisms.

Mitigation Strategies

Immediately update the firmware to a patched version if available. Disable the backup/restore feature if not required. Restrict access to the /cgi-bin/backup endpoint. Monitor network traffic for unauthorized backup downloads. Consider replacing the device if no patch is provided.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102241. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart