Description
A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A stack‑based buffer overflow exists in the password‑check function of the authentication module on Netcore NR289‑GE firmware 1.4.5102. The vulnerability is identified as CWE‑119 and CWE‑121. The flaw allows an attacker to send a specially crafted Username argument that overflows the stack. Based on the description, it is inferred that exploitation can lead to arbitrary code execution or a complete device takeover if the attacker can achieve sufficient control over the overflowed area. The public exploit demonstrates that the bug can be triggered without prior authentication, indicating that the flaw can be abused by unauthenticated users. The impact is thus a critical loss of confidentiality, integrity, and availability for the affected device.

Affected Systems

The problem affects Netcore routers running firmware version 1.4.5102 under the NR289‑GE model. No other firmware revisions or device models are mentioned as vulnerable.

Risk and Exploitability

The CVSS score of 9.3 reflects a high severity and a high likelihood of successful exploitation. EPSS data is not available, but the existence of a public exploit and the lack of a vendor fix keep the risk elevated. Attackers may launch the exploit remotely without authentication, and the flaw is not listed in CISA’s KEV catalog; nevertheless, the impact remains severe.

Generated by OpenCVE AI on September 28, 2026 at 16:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install a newer Netcore NR289‑GE firmware that includes the password‑check stack‑overflow fix; confirm the release notes list the vulnerability remediation.
  • If no updated firmware is available, immediately restrict remote access to the device’s authentication endpoint by configuring firewall rules to allow traffic only from known trusted IP ranges or by disabling the /bin/boa service entirely.
  • Enable detailed logging for authentication attempts and set up intrusion detection to alert on repeated failed login attempts or suspicious payloads targeting the /bin/boa endpoint, and investigate any alerts promptly.

Generated by OpenCVE AI on September 28, 2026 at 16:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Netcore NR289-GE Authentication boa password-check stack-based overflow
First Time appeared Netcore
Netcore nr289-ge
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:netcore:nr289-ge:*:*:*:*:*:*:*:*
Vendors & Products Netcore
Netcore nr289-ge
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Netcore Nr289-ge
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T15:21:44.812Z

Reserved: 2026-09-27T17:48:00.794Z

Link: CVE-2026-101074

cve-icon Vulnrichment

Updated: 2026-09-28T15:21:35.161Z

cve-icon NVD

Status : Received

Published: 2026-09-28T15:17:12.830

Modified: 2026-09-28T16:17:11.787

Link: CVE-2026-101074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T18:30:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow