Overview
Netcore's NR289-GE SMB router is affected by a critical, pre-authentication stack-based buffer overflow tracked as CVE-2026-101074. The flaw lives in the password-check function of the /bin/boa web server's Authentication component: the Username argument is copied into fixed-size stack buffers without a length check, and because the overflow happens before any credential validation, it can be triggered by any remote, unauthenticated request.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-101074 |
| Severity | Critical |
| CVSS 3.1 Score | 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
| Attack Vector | Network |
| Authentication | None Required |
| Privileges Required | None |
| CWE | CWE-121 (Stack-Based Buffer Overflow) |
| Component/Function | password-check in /bin/boa (Authentication) |
Public technical analysis indicates the password-check routine Base64-decodes the Username value and copies it into two 64-byte stack buffers; the decode path accepts roughly 129 bytes of decoded input, so a username longer than 96 bytes overwrites adjacent saved registers on the stack. On the device's MIPS32 big-endian target, that overwrite gives an attacker a path to hijack the program counter and chain a ROP payload against uClibc — turning a single crafted authentication request into denial of service at minimum, and potential remote code execution at worst. A proof-of-concept exploit is reportedly public.
Why This Matters
- No authentication or user interaction is required — a single malicious HTTP request to the boa web management interface can trigger the overflow
- Impact ranges from denial of service to full remote code execution, since the overwrite occurs before any credentials are checked and can corrupt saved return addresses
- Public proof-of-concept exploit code lowers the bar for mass exploitation, especially against internet-exposed management interfaces
- The vendor reportedly has not responded to disclosure, so no official firmware fix currently exists
- NR289-GE units are frequently deployed as SMB/branch routers, meaning a compromise can expose an entire local network or serve as a pivot point or botnet node
- This CVE was disclosed alongside several other Authentication-related flaws in the same firmware (including auth-bypass and command-injection issues), suggesting broader hardening is needed across the
/bin/boaservice, not just this one function
Remediation
- Check for a firmware update from Netcore and apply it immediately if one becomes available — as of publication, no vendor patch has been confirmed
- Never expose the router's web management interface to the internet; restrict access to trusted LAN/VLAN segments only
- Firewall or disable remote administration on the WAN interface until a fix is confirmed
- Segment NR289-GE devices behind a firewall or on an isolated management VLAN, away from sensitive internal systems
- Monitor for crashes or unexpected reboots of the boa web service, which may indicate exploitation attempts
- Consider replacing affected devices with actively supported hardware if Netcore does not issue a fix, given the unresponsive vendor disclosure history so far
With a CVSS 9.8 score, no authentication barrier, and a reported public proof-of-concept, this vulnerability should be treated as an active exploitation risk on any internet-facing NR289-GE deployment.