Impact
A stack‑based buffer overflow exists in the password‑check function of the authentication module on Netcore NR289‑GE firmware 1.4.5102. The vulnerability is identified as CWE‑119 and CWE‑121. The flaw allows an attacker to send a specially crafted Username argument that overflows the stack. Based on the description, it is inferred that exploitation can lead to arbitrary code execution or a complete device takeover if the attacker can achieve sufficient control over the overflowed area. The public exploit demonstrates that the bug can be triggered without prior authentication, indicating that the flaw can be abused by unauthenticated users. The impact is thus a critical loss of confidentiality, integrity, and availability for the affected device.
Affected Systems
The problem affects Netcore routers running firmware version 1.4.5102 under the NR289‑GE model. No other firmware revisions or device models are mentioned as vulnerable.
Risk and Exploitability
The CVSS score of 9.3 reflects a high severity and a high likelihood of successful exploitation. EPSS data is not available, but the existence of a public exploit and the lack of a vendor fix keep the risk elevated. Attackers may launch the exploit remotely without authentication, and the flaw is not listed in CISA’s KEV catalog; nevertheless, the impact remains severe.
OpenCVE Enrichment