Impact
A flaw exists in the /bin/boa CGI dispatcher on Netcore NR289-GE routers that allows an attacker to bypass authentication. The vulnerability is a form of improper authentication, which can lead to unauthorized command execution or privileged configuration changes on the device. The flaw is categorized as CWE-287 and can be triggered remotely through crafted requests.
Affected Systems
The only known affected product is the Netcore NR289-GE router running firmware version 1.4.5102. No other models or firmware versions have been reported to be impacted by this specific CGI dispatcher issue.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk. Exploitation code has been released publicly, so an attacker can initiate the attack from outside the network. The EPSS score is not available, making the precise likelihood of exploitation uncertain, yet the lack of a vendor response and the public nature of the exploit raise concern. The vulnerability is not listed in the CISA KEV catalog, but given its remote trigger and authentication bypass capability, it remains a significant risk to exposed Netcore devices.
OpenCVE Enrichment