SECURITYCRITICALCVE-2026-101076

CVE-2026-101076: Netcore NR289-GE Router Unauthenticated OS Command Injection

A critical, unauthenticated OS command injection in Netcore NR289-GE routers has a public exploit, letting remote attackers run commands as root.

Dylan H.

Security Team

September 29, 2026
3 min read
CVE-2026-101076: Netcore NR289-GE Router Unauthenticated OS Command Injection

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Netcore NR289-GE — firmware 1.4.5102 (and earlier, if applicable)

Overview

Netcore NR289-GE routers running firmware 1.4.5102 are affected by a critical, unauthenticated OS command injection vulnerability tracked as CVE-2026-101076, carrying the maximum possible CVSS score of 10.0. The flaw lives in the /set_ntp_server_ip.cgi endpoint of the device's CGI Handler component, where the ntp_ip argument is passed unsanitized into a system() call, letting a remote, unauthenticated attacker execute arbitrary operating-system commands. A working exploit for this vulnerability is already public, dramatically raising the urgency for anyone running this device.


Technical Details

FieldValue
CVE IDCVE-2026-101076
SeverityCritical
CVSS Score10.0 (CVSS 3.1 and CVSS 4.0)
Attack VectorNetwork
AuthenticationNone Required
Privileges RequiredNone
CWECWE-78 (OS Command Injection), CWE-77 (Command Injection)
Component/Function/set_ntp_server_ip.cgi — CGI Handler, system function, ntp_ip argument
Exploit StatusPublic — proof-of-concept exploit code is available

Why This Matters

  • The exploit is public, meaning any attacker — not just a sophisticated one — can weaponize this flaw today; mass scanning and automated exploitation of internet-exposed devices should be expected imminently
  • No authentication or user interaction is required — a single malicious request to the CGI handler is enough to trigger command execution
  • Successful exploitation grants command execution with root-level privileges, potentially handing an attacker full control of the router, including traffic interception, firmware tampering, and use as a foothold or botnet node inside the local network
  • The vendor was reportedly contacted about this disclosure and, as of publication, has not responded or released a fix — there is currently no official patch
  • This is one of multiple concurrently disclosed vulnerabilities in the same NR289-GE 1.4.5102 firmware, including CVE-2026-101074 (buffer overflow in the password-check routine), CVE-2026-101075 (OS command injection in location_time.cgi), and CVE-2026-101077 (missing authentication in the boa_temp handler) — a device with this many concurrent critical flaws should be treated as thoroughly compromised-by-design until patched

Remediation

  1. Check with Netcore for an updated firmware release addressing CVE-2026-101076 and the companion CVEs affecting the NR289-GE 1.4.5102 line; apply it immediately once available
  2. Disable remote/WAN-facing management on the device and restrict the CGI/admin interface to trusted LAN segments only
  3. Firewall or network-segment the device so /set_ntp_server_ip.cgi and other CGI handlers are unreachable from untrusted networks or the public internet
  4. Avoid configuring NTP via the web/CGI interface if an alternate configuration path exists, to reduce exposure of the vulnerable code
  5. Given the critical severity combined with multiple concurrent flaws in this firmware, strongly consider replacing the device if Netcore does not ship a fix in a reasonable timeframe
  6. Treat any NR289-GE device that has been reachable from an untrusted network as potentially compromised — factory reset and reflash once a fix is available, then rotate any credentials that may have transited the device

With a maximum CVSS score of 10.0, no authentication barrier, and a publicly available exploit, this vulnerability should be treated as an active or imminent exploitation risk.