SECURITYCRITICALCVE-2026-101074

CVE-2026-101074: Netcore NR289-GE Pre-Authentication Stack Buffer Overflow

A critical pre-auth stack buffer overflow in Netcore NR289-GE routers lets remote attackers crash the device or potentially achieve RCE.

Dylan H.

Security Team

September 29, 2026
3 min read
CVE-2026-101074: Netcore NR289-GE Pre-Authentication Stack Buffer Overflow

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Netcore NR289-GE — firmware 1.4.5102 (and earlier, if applicable)

Overview

Netcore's NR289-GE SMB router is affected by a critical, pre-authentication stack-based buffer overflow tracked as CVE-2026-101074. The flaw lives in the password-check function of the /bin/boa web server's Authentication component: the Username argument is copied into fixed-size stack buffers without a length check, and because the overflow happens before any credential validation, it can be triggered by any remote, unauthenticated request.


Technical Details

FieldValue
CVE IDCVE-2026-101074
SeverityCritical
CVSS 3.1 Score9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Attack VectorNetwork
AuthenticationNone Required
Privileges RequiredNone
CWECWE-121 (Stack-Based Buffer Overflow)
Component/Functionpassword-check in /bin/boa (Authentication)

Public technical analysis indicates the password-check routine Base64-decodes the Username value and copies it into two 64-byte stack buffers; the decode path accepts roughly 129 bytes of decoded input, so a username longer than 96 bytes overwrites adjacent saved registers on the stack. On the device's MIPS32 big-endian target, that overwrite gives an attacker a path to hijack the program counter and chain a ROP payload against uClibc — turning a single crafted authentication request into denial of service at minimum, and potential remote code execution at worst. A proof-of-concept exploit is reportedly public.


Why This Matters

  • No authentication or user interaction is required — a single malicious HTTP request to the boa web management interface can trigger the overflow
  • Impact ranges from denial of service to full remote code execution, since the overwrite occurs before any credentials are checked and can corrupt saved return addresses
  • Public proof-of-concept exploit code lowers the bar for mass exploitation, especially against internet-exposed management interfaces
  • The vendor reportedly has not responded to disclosure, so no official firmware fix currently exists
  • NR289-GE units are frequently deployed as SMB/branch routers, meaning a compromise can expose an entire local network or serve as a pivot point or botnet node
  • This CVE was disclosed alongside several other Authentication-related flaws in the same firmware (including auth-bypass and command-injection issues), suggesting broader hardening is needed across the /bin/boa service, not just this one function

Remediation

  1. Check for a firmware update from Netcore and apply it immediately if one becomes available — as of publication, no vendor patch has been confirmed
  2. Never expose the router's web management interface to the internet; restrict access to trusted LAN/VLAN segments only
  3. Firewall or disable remote administration on the WAN interface until a fix is confirmed
  4. Segment NR289-GE devices behind a firewall or on an isolated management VLAN, away from sensitive internal systems
  5. Monitor for crashes or unexpected reboots of the boa web service, which may indicate exploitation attempts
  6. Consider replacing affected devices with actively supported hardware if Netcore does not issue a fix, given the unresponsive vendor disclosure history so far

With a CVSS 9.8 score, no authentication barrier, and a reported public proof-of-concept, this vulnerability should be treated as an active exploitation risk on any internet-facing NR289-GE deployment.