Overview
Netcore NR289-GE routers running firmware 1.4.5102 are affected by a maximum-severity, unauthenticated OS command injection vulnerability tracked as CVE-2026-101075. The flaw lives in the system function of /location_time.cgi, part of the device's Location Time Handler, where the mac argument is passed into a shell command without sanitization. A remote attacker can exploit this over the network with no credentials and no user interaction, earning it a perfect CVSS score of 10.0. Public technical details and exploit code are already circulating, and Netcore has not responded to disclosure attempts.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-101075 |
| Severity | Critical |
| CVSS Score | 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) |
| Attack Vector | Network |
| Authentication | None Required |
| Privileges Required | None |
| CWE | CWE-78 (OS Command Injection) |
| Component/Function | /location_time.cgi — Location Time Handler, system call via the mac parameter |
Why This Matters
- A CVSS score of 10.0 reflects the worst-case combination: network-reachable, low complexity, no authentication, no user interaction, and complete impact to confidentiality, integrity, and availability
- A remote attacker can inject arbitrary OS commands that execute with the privileges of the CGI process — typically root on embedded router firmware — resulting in full device takeover
- Public exploit details are already available and the vendor has not responded to disclosure, meaning no official firmware fix currently exists
- A compromised router can be used to intercept or redirect LAN traffic, hijack DNS, exfiltrate credentials, or serve as a persistent foothold and botnet node inside the network it was meant to protect
- The
macparameter is a value routers frequently expose or accept from client-facing interfaces, making this an easy target for automated scanning and mass exploitation once weaponized - NR289-GE units are affected by multiple concurrently disclosed critical flaws — including CVE-2026-101074 (buffer overflow in the password-check routine), CVE-2026-101076 (OS command injection in
set_ntp_server_ip.cgi), and CVE-2026-101077 (missing authentication in theboa_temphandler) — so a single exposed device may be reachable through several independent attack paths
Remediation
- Check for a firmware update from Netcore and apply it immediately if one becomes available — as of publication, no official patch has been released
- Never expose the router's CGI/management interface to the internet. Block inbound WAN access to
/location_time.cgiand other.cgiendpoints at the network edge - Segment the device onto an isolated management VLAN, away from trusted LAN and IoT traffic
- Disable remote/WAN-side management features on the device if the option exists
- Restrict LAN access to the web/CGI management interface using firewall rules or an access control list limited to known administrative hosts
- Monitor for anomalous behavior — unexpected outbound connections, new processes, or configuration changes — on any device that was reachable from untrusted networks prior to mitigation
- Plan for hardware replacement if Netcore does not issue a fix; treat unpatched, internet-exposed units as compromised and reflash or retire them
With a perfect CVSS 10.0 score, no authentication barrier, and exploit details already public, this vulnerability should be treated as an imminent, active exploitation risk.