Overview
Netcore NR289-GE routers running firmware 1.4.5102 are affected by a critical, unauthenticated OS command injection vulnerability tracked as CVE-2026-101076, carrying the maximum possible CVSS score of 10.0. The flaw lives in the /set_ntp_server_ip.cgi endpoint of the device's CGI Handler component, where the ntp_ip argument is passed unsanitized into a system() call, letting a remote, unauthenticated attacker execute arbitrary operating-system commands. A working exploit for this vulnerability is already public, dramatically raising the urgency for anyone running this device.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-101076 |
| Severity | Critical |
| CVSS Score | 10.0 (CVSS 3.1 and CVSS 4.0) |
| Attack Vector | Network |
| Authentication | None Required |
| Privileges Required | None |
| CWE | CWE-78 (OS Command Injection), CWE-77 (Command Injection) |
| Component/Function | /set_ntp_server_ip.cgi — CGI Handler, system function, ntp_ip argument |
| Exploit Status | Public — proof-of-concept exploit code is available |
Why This Matters
- The exploit is public, meaning any attacker — not just a sophisticated one — can weaponize this flaw today; mass scanning and automated exploitation of internet-exposed devices should be expected imminently
- No authentication or user interaction is required — a single malicious request to the CGI handler is enough to trigger command execution
- Successful exploitation grants command execution with root-level privileges, potentially handing an attacker full control of the router, including traffic interception, firmware tampering, and use as a foothold or botnet node inside the local network
- The vendor was reportedly contacted about this disclosure and, as of publication, has not responded or released a fix — there is currently no official patch
- This is one of multiple concurrently disclosed vulnerabilities in the same NR289-GE 1.4.5102 firmware, including CVE-2026-101074 (buffer overflow in the password-check routine), CVE-2026-101075 (OS command injection in
location_time.cgi), and CVE-2026-101077 (missing authentication in theboa_temphandler) — a device with this many concurrent critical flaws should be treated as thoroughly compromised-by-design until patched
Remediation
- Check with Netcore for an updated firmware release addressing CVE-2026-101076 and the companion CVEs affecting the NR289-GE 1.4.5102 line; apply it immediately once available
- Disable remote/WAN-facing management on the device and restrict the CGI/admin interface to trusted LAN segments only
- Firewall or network-segment the device so
/set_ntp_server_ip.cgiand other CGI handlers are unreachable from untrusted networks or the public internet - Avoid configuring NTP via the web/CGI interface if an alternate configuration path exists, to reduce exposure of the vulnerable code
- Given the critical severity combined with multiple concurrent flaws in this firmware, strongly consider replacing the device if Netcore does not ship a fix in a reasonable timeframe
- Treat any NR289-GE device that has been reachable from an untrusted network as potentially compromised — factory reset and reflash once a fix is available, then rotate any credentials that may have transited the device
With a maximum CVSS score of 10.0, no authentication barrier, and a publicly available exploit, this vulnerability should be treated as an active or imminent exploitation risk.