Description
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows an attacker to supply arbitrary input to the ntp_ip argument of the HTTP CGI /set_ntp_server_ip.cgi on Netcore NR289‑GE firmware, resulting in operating‑system command injection that can be exploited remotely. An attacker who can reach the CGI interface can execute any shell command as the CGI process, giving full control over the device. The flaw resides in unsanitized user input being passed directly to system commands.

Affected Systems

The flaw exists in Netcore NR289‑GE routers running firmware version 1.4.5102. No other product or version information is listed, so devices that have not been patched to a newer firmware are at risk.

Risk and Exploitability

The CVSS score of 10 indicates maximum severity, and the public nature of the exploit lowers the exploitation barrier. Though EPSS is not available and the vulnerability is not in the KEV catalog, the remote attack vector and lack of input validation mean that an attacker can achieve full device compromise without additional access. The likely attack path is through an HTTP request to the vulnerable CGI handler, which can be executed from outside the device network.

Generated by OpenCVE AI on September 28, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to a version that contains the fix; if no updated firmware is available, contact Netcore for remediation.
  • If an upgrade is not possible, block or filter external access to the /set_ntp_server_ip.cgi endpoint using the device firewall or an external firewall to limit the interface to local traffic only.
  • Disable NTP configuration changes via the web interface if possible, or reset the NTP settings to static values, thereby reducing the exposure of the vulnerable endpoint.
  • Continuously monitor device logs for repeated attempts to access /set_ntp_server_ip.cgi or unexpected command execution patterns.

Generated by OpenCVE AI on September 28, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection
First Time appeared Netcore
Netcore nr289-ge
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:netcore:nr289-ge:*:*:*:*:*:*:*:*
Vendors & Products Netcore
Netcore nr289-ge
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 10, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Netcore Nr289-ge
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T15:00:07.606Z

Reserved: 2026-09-27T17:48:08.544Z

Link: CVE-2026-101076

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T16:17:11.947

Modified: 2026-09-28T16:17:11.947

Link: CVE-2026-101076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T18:30:04Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')