SECURITYCRITICALCVE-2026-101077

CVE-2026-101077: Netcore NR289-GE Authentication Bypass in the boa_temp Handler

A critical, CVSS 10 missing-authentication flaw in Netcore NR289-GE routers has a public exploit and an unresponsive vendor, with no patch in sight.

Dylan H.

Security Team

September 29, 2026
3 min read
CVE-2026-101077: Netcore NR289-GE Authentication Bypass in the boa_temp Handler

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Netcore NR289-GE — firmware 1.4.5102 (and earlier, if applicable)

Overview

Netcore NR289-GE routers running firmware 1.4.5102 are affected by a critical missing authentication vulnerability tracked as CVE-2026-101077. The flaw lives in the process_request function of the device's boa_temp Handler component, where the built-in Boa web server fails to enforce authentication on a request path that should require it, allowing a remote, unauthenticated attacker to reach protected device functionality. A public exploit is already available, exploitation is described as easy, and the vendor — contacted early in the disclosure process — has not responded in any way, meaning there is no indication a patch is forthcoming.


Technical Details

FieldValue
CVE IDCVE-2026-101077
SeverityCritical
CVSS Score10.0 (CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Attack VectorNetwork
AuthenticationNone Required
Privileges RequiredNone
CWECWE-306 (Missing Authentication for Critical Function)
Component / Functionboa_temp Handler — process_request()
Exploit StatusPublic
Vendor ResponseNone

The vulnerability stems from the Boa embedded web server used by the NR289-GE firmware: the process_request routine in the boa_temp handler does not verify that a caller is authenticated before servicing the request. Because the manipulation requires no special input beyond reaching the endpoint, and no authentication or user interaction is needed, remote exploitation is straightforward and has already been demonstrated in a published proof-of-concept.


Why This Matters

  • No authentication barrier stands between a remote attacker and functionality that should be gated behind a login
  • A working exploit is already public, so this moves straight to active-exploitation risk rather than a theoretical one
  • The vendor was notified early and never responded — there is no vendor advisory, no timeline, and no indication a firmware fix is being developed
  • This is one of at least four concurrent CVEs disclosed against the same NR289-GE 1.4.5102 firmware (CVE-2026-101074, a stack-based buffer overflow in the password-check routine; CVE-2026-101075 and CVE-2026-101076, OS command injection flaws in location_time.cgi and set_ntp_server_ip.cgi respectively) — the device's exposure surface is broader than any single advisory suggests
  • Devices left reachable from the internet or an untrusted network segment should be treated as already compromised or imminently exploitable

Remediation

Since Netcore has not acknowledged the report and no patched firmware exists, mitigation must happen at the network layer:

  1. Remove the device from direct internet exposure — do not port-forward or place the NR289-GE's management or web interfaces on a WAN-facing address
  2. Disable remote management entirely if the firmware exposes such a toggle, and restrict the web management interface to a trusted LAN/VLAN only
  3. Segment the device behind a firewall or on an isolated VLAN so a compromise cannot pivot into the broader network
  4. Monitor for anomalous traffic to and from the device, including unexpected outbound connections that could indicate the device has been recruited into a botnet
  5. Plan to replace the device with hardware from a vendor that has a track record of responding to vulnerability disclosures — given the lack of any vendor response, long-term reliance on this hardware carries open-ended risk

With no vendor acknowledgment, no patch timeline, and a public exploit already circulating, every day the NR289-GE stays in service compounds the long-term risk rather than reducing it.