Impact
A flaw in the Netcore NR289-GE 1.4.5102 router firmware allows a remote attacker to inject arbitrary operating system commands through the /ap_ip.cgi CGI script. The vulnerability originates when the ip parameter is not properly validated, enabling attackers to execute commands with the privileges of the web server process. This can result in full compromise of the router, data exfiltration, or use of the device as a pivot point for further attacks.
Affected Systems
The vulnerability affects Netcore NR289-GE routers running firmware version 1.4.5102. No other versions or products were identified as impacted in the advisory.
Risk and Exploitability
The CVSS base score of 10 indicates maximum severity, and the exploit is publicly documented, suggesting it is readily available to attackers. Although EPSS data is not available, the lack of a KEV listing does not diminish the risk; the attack vector is remote via HTTP, and the flaw permits remote code execution without authentication. Consequently, the overall threat level remains critical.
OpenCVE Enrichment