SECURITYCRITICALCVE-2026-101075

CVE-2026-101075: Netcore NR289-GE Unauthenticated OS Command Injection

A critical OS command injection in Netcore NR289-GE routers lets unauthenticated attackers execute root commands via location_time.cgi.

Dylan H.

Security Team

September 29, 2026
3 min read
CVE-2026-101075: Netcore NR289-GE Unauthenticated OS Command Injection

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Netcore NR289-GE — firmware 1.4.5102 (and earlier, if applicable)

Overview

Netcore NR289-GE routers running firmware 1.4.5102 are affected by a maximum-severity, unauthenticated OS command injection vulnerability tracked as CVE-2026-101075. The flaw lives in the system function of /location_time.cgi, part of the device's Location Time Handler, where the mac argument is passed into a shell command without sanitization. A remote attacker can exploit this over the network with no credentials and no user interaction, earning it a perfect CVSS score of 10.0. Public technical details and exploit code are already circulating, and Netcore has not responded to disclosure attempts.


Technical Details

FieldValue
CVE IDCVE-2026-101075
SeverityCritical
CVSS Score10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Attack VectorNetwork
AuthenticationNone Required
Privileges RequiredNone
CWECWE-78 (OS Command Injection)
Component/Function/location_time.cgi — Location Time Handler, system call via the mac parameter

Why This Matters

  • A CVSS score of 10.0 reflects the worst-case combination: network-reachable, low complexity, no authentication, no user interaction, and complete impact to confidentiality, integrity, and availability
  • A remote attacker can inject arbitrary OS commands that execute with the privileges of the CGI process — typically root on embedded router firmware — resulting in full device takeover
  • Public exploit details are already available and the vendor has not responded to disclosure, meaning no official firmware fix currently exists
  • A compromised router can be used to intercept or redirect LAN traffic, hijack DNS, exfiltrate credentials, or serve as a persistent foothold and botnet node inside the network it was meant to protect
  • The mac parameter is a value routers frequently expose or accept from client-facing interfaces, making this an easy target for automated scanning and mass exploitation once weaponized
  • NR289-GE units are affected by multiple concurrently disclosed critical flaws — including CVE-2026-101074 (buffer overflow in the password-check routine), CVE-2026-101076 (OS command injection in set_ntp_server_ip.cgi), and CVE-2026-101077 (missing authentication in the boa_temp handler) — so a single exposed device may be reachable through several independent attack paths

Remediation

  1. Check for a firmware update from Netcore and apply it immediately if one becomes available — as of publication, no official patch has been released
  2. Never expose the router's CGI/management interface to the internet. Block inbound WAN access to /location_time.cgi and other .cgi endpoints at the network edge
  3. Segment the device onto an isolated management VLAN, away from trusted LAN and IoT traffic
  4. Disable remote/WAN-side management features on the device if the option exists
  5. Restrict LAN access to the web/CGI management interface using firewall rules or an access control list limited to known administrative hosts
  6. Monitor for anomalous behavior — unexpected outbound connections, new processes, or configuration changes — on any device that was reachable from untrusted networks prior to mitigation
  7. Plan for hardware replacement if Netcore does not issue a fix; treat unpatched, internet-exposed units as compromised and reflash or retire them

With a perfect CVSS 10.0 score, no authentication barrier, and exploit details already public, this vulnerability should be treated as an imminent, active exploitation risk.