Skip to content
Threat Feed
critical advisory

Remote Command Injection in Netcore NR289-GE

Netcore NR289-GE version 1.4.5102 is vulnerable to remote unauthenticated OS command injection via the ip argument in the /ap_ip.cgi component.

CVE search metadata

CVE search record: CVE-2026-101072. Severity: critical. CVSS: 10.0. KEV: no. Product: NR289-GE (1.4.5102). Brief: Remote Command Injection in Netcore NR289-GE. Brief link: https://feed.craftedsignal.io/briefs/2026-09-netcore-cve/

What's new

  • 1. added coverage for NR289-GE (1.4.5102) Sep 28, 16:20 via nvd
  • 2. added detection rule: Detects CVE-2026-101075 Exploitation - OS Command Injection via /location_time.cgi Sep 28, 16:20 via nvd

A critical security vulnerability has been identified in the Netcore NR289-GE router, specifically in version 1.4.5102. The flaw resides within the CGI handler component, specifically the /ap_ip.cgi script. An unauthenticated remote attacker can inject arbitrary operating system commands by manipulating the 'ip' HTTP GET or POST parameter. Because the CGI handler processes this input without sufficient sanitization before passing it to a system shell, the vulnerability allows for full system compromise with the privileges of the web server process. The vendor has not responded to disclosure attempts, and proof-of-concept exploit code is publicly available, increasing the risk of exploitation by opportunistic threat actors targeting edge devices.

Impact

Successful exploitation of this vulnerability results in full remote control of the affected Netcore NR289-GE device. Potential impacts include unauthorized access to internal network traffic, lateral movement into the local network, and the deployment of persistent malware or backdoors on the gateway device. Given the critical 10.0 CVSS score, this vulnerability poses a severe risk to any organization utilizing these routers in internet-facing configurations.

Recommendation

Deploy network-level detection for the suspicious HTTP requests associated with this exploit. Since the vendor has not provided a patch, administrators should prioritize restricting access to the web management interface of the NR289-GE to trusted IP ranges only. If remote management is not required, disable the web management interface entirely until a vendor-supplied firmware update becomes available.


Immediate actions

Restrict access to /ap_ip.cgi on Netcore NR289-GE devices via ACLs

Network Security 24h

Threat Hunt

Search logs for requests to /ap_ip.cgi containing shell metacharacters

T1203 high high confidence hunt now

Data: Web server access logs

Mitigations

Disable external access to web management interface

immediate Network Security

CVE-2026-101072

Detection coverage 2

Detects CVE-2026-101072 Exploitation - OS Command Injection via /ap_ip.cgi

critical

Detects exploitation attempts against Netcore NR289-GE where the ip argument contains common shell injection characters.

sigma tactics: execution, initial_access techniques: T1203 sources: webserver

Detects CVE-2026-101075 Exploitation - OS Command Injection via /location_time.cgi

critical

Detects exploitation attempts against CVE-2026-101075 by identifying shell metacharacters in the mac parameter of the /location_time.cgi endpoint

sigma tactics: execution, initial_access techniques: T1203 sources: webserver

Detection queries are available on the platform. Get full rules →