Impact
This vulnerability allows an attacker to supply arbitrary input to the ntp_ip argument of the HTTP CGI /set_ntp_server_ip.cgi on Netcore NR289‑GE firmware, resulting in operating‑system command injection that can be exploited remotely. An attacker who can reach the CGI interface can execute any shell command as the CGI process, giving full control over the device. The flaw resides in unsanitized user input being passed directly to system commands.
Affected Systems
The flaw exists in Netcore NR289‑GE routers running firmware version 1.4.5102. No other product or version information is listed, so devices that have not been patched to a newer firmware are at risk.
Risk and Exploitability
The CVSS score of 10 indicates maximum severity, and the public nature of the exploit lowers the exploitation barrier. Though EPSS is not available and the vulnerability is not in the KEV catalog, the remote attack vector and lack of input validation mean that an attacker can achieve full device compromise without additional access. The likely attack path is through an HTTP request to the vulnerable CGI handler, which can be executed from outside the device network.
OpenCVE Enrichment