Description
A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access
Action: Apply Patch
AI Analysis

Impact

A flaw exists in the /bin/boa CGI dispatcher on Netcore NR289-GE routers that allows an attacker to bypass authentication. The vulnerability is a form of improper authentication, which can lead to unauthorized command execution or privileged configuration changes on the device. The flaw is categorized as CWE-287 and can be triggered remotely through crafted requests.

Affected Systems

The only known affected product is the Netcore NR289-GE router running firmware version 1.4.5102. No other models or firmware versions have been reported to be impacted by this specific CGI dispatcher issue.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate risk. Exploitation code has been released publicly, so an attacker can initiate the attack from outside the network. The EPSS score is not available, making the precise likelihood of exploitation uncertain, yet the lack of a vendor response and the public nature of the exploit raise concern. The vulnerability is not listed in the CISA KEV catalog, but given its remote trigger and authentication bypass capability, it remains a significant risk to exposed Netcore devices.

Generated by OpenCVE AI on September 28, 2026 at 15:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify all Netcore NR289-GE routers running firmware 1.4.5102 and confirm that the CGI dispatcher component is present
  • Apply the latest firmware update for NR289-GE from Netcore or a vendor‑approved patch addressing the authentication bypass; if no update exists, contact Netcore for a custom fix
  • As an interim measure, block remote access to the /bin/boa URL or disable the CGI dispatcher service to prevent unauthorized requests on the affected routers
  • Monitor firewall and router authentication logs for unusual activity and enforce network segmentation to limit external exposure of the routers

Generated by OpenCVE AI on September 28, 2026 at 15:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Netcore NR289-GE CGI Dispatcher boa improper authentication
First Time appeared Netcore
Netcore nr289-ge
Weaknesses CWE-287
CPEs cpe:2.3:a:netcore:nr289-ge:*:*:*:*:*:*:*:*
Vendors & Products Netcore
Netcore nr289-ge
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Netcore Nr289-ge
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T14:00:09.779Z

Reserved: 2026-09-27T17:47:57.469Z

Link: CVE-2026-101073

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T15:17:12.603

Modified: 2026-09-28T15:17:12.603

Link: CVE-2026-101073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:22:10Z

Weaknesses