Description
A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

A remote attacker can exploit an OS command injection flaw in the Netcore NR289-GE router’s /location_time.cgi handler by manipulating the mac query parameter. The vulnerability allows execution of arbitrary shell commands, granting full control over the device and any services running on it. The vendor has not responded to details, and the flaw is publicly documented, which increases the risk of widespread exploitation.

Affected Systems

The affected product is the Netcore NR289-GE router running firmware version 1.4.5102. No other versions are listed in the CNA data, so the impact is limited to this specific build.

Risk and Exploitability

The flaw carries a CVSS score of 10, indicating extreme severity. The EPSS score is unavailable, but the risk remains high due to its public disclosure and lack of vendor response. The vulnerability is not listed in the CISA KEV catalog, though its impact is nonetheless significant. Attackers can remotely trigger the malicious macro by sending crafted requests to the vulnerable endpoint over the network.

Generated by OpenCVE AI on September 28, 2026 at 16:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released firmware update that addresses the command‑injection issue once it becomes available.
  • If an update cannot be obtained immediately, block external access to /location_time.cgi or prioritize disabling the Location Time Handler component via the device’s configuration or a network firewall rule.
  • Segregate the affected device from critical network segments and monitor traffic for suspicious activity until a permanent fix can be applied.

Generated by OpenCVE AI on September 28, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Netcore NR289-GE Location Time location_time.cgi system os command injection
First Time appeared Netcore
Netcore nr289-ge
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:netcore:nr289-ge:*:*:*:*:*:*:*:*
Vendors & Products Netcore
Netcore nr289-ge
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 10, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Netcore Nr289-ge
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T16:27:41.533Z

Reserved: 2026-09-27T17:48:04.788Z

Link: CVE-2026-101075

cve-icon Vulnrichment

Updated: 2026-09-28T16:27:36.987Z

cve-icon NVD

Status : Received

Published: 2026-09-28T15:17:13.043

Modified: 2026-09-28T17:17:47.493

Link: CVE-2026-101075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:30:03Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')