Impact
A remote attacker can exploit an OS command injection flaw in the Netcore NR289-GE router’s /location_time.cgi handler by manipulating the mac query parameter. The vulnerability allows execution of arbitrary shell commands, granting full control over the device and any services running on it. The vendor has not responded to details, and the flaw is publicly documented, which increases the risk of widespread exploitation.
Affected Systems
The affected product is the Netcore NR289-GE router running firmware version 1.4.5102. No other versions are listed in the CNA data, so the impact is limited to this specific build.
Risk and Exploitability
The flaw carries a CVSS score of 10, indicating extreme severity. The EPSS score is unavailable, but the risk remains high due to its public disclosure and lack of vendor response. The vulnerability is not listed in the CISA KEV catalog, though its impact is nonetheless significant. Attackers can remotely trigger the malicious macro by sending crafted requests to the vulnerable endpoint over the network.
OpenCVE Enrichment