Description
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Remote OS Command Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Netcore NR289-GE 1.4.5102 router firmware allows a remote attacker to inject arbitrary operating system commands through the /ap_ip.cgi CGI script. The vulnerability originates when the ip parameter is not properly validated, enabling attackers to execute commands with the privileges of the web server process. This can result in full compromise of the router, data exfiltration, or use of the device as a pivot point for further attacks.

Affected Systems

The vulnerability affects Netcore NR289-GE routers running firmware version 1.4.5102. No other versions or products were identified as impacted in the advisory.

Risk and Exploitability

The CVSS base score of 10 indicates maximum severity, and the exploit is publicly documented, suggesting it is readily available to attackers. Although EPSS data is not available, the lack of a KEV listing does not diminish the risk; the attack vector is remote via HTTP, and the flaw permits remote code execution without authentication. Consequently, the overall threat level remains critical.

Generated by OpenCVE AI on September 28, 2026 at 15:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or firmware update that addresses the command injection issue in the /ap_ip.cgi handler.
  • If a patch is not yet released, block external access to the router’s management interface using a firewall or place the device behind a VPN to limit exposure to trusted networks.
  • Configure the web server to deny or restrict access to the /ap_ip.cgi endpoint for all external hosts until a fix is applied.

Generated by OpenCVE AI on September 28, 2026 at 15:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Netcore NR289-GE CGI ap_ip.cgi system os command injection
First Time appeared Netcore
Netcore nr289-ge
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:netcore:nr289-ge:*:*:*:*:*:*:*:*
Vendors & Products Netcore
Netcore nr289-ge
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 10, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Netcore Nr289-ge
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T13:58:31.869Z

Reserved: 2026-09-27T17:47:51.808Z

Link: CVE-2026-101072

cve-icon Vulnrichment

Updated: 2026-09-28T13:58:14.419Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:13.973

Modified: 2026-09-28T15:16:04.793

Link: CVE-2026-101072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T17:00:05Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')