Remote Command Injection in Netcore NR289-GE
Netcore NR289-GE version 1.4.5102 is vulnerable to remote unauthenticated OS command injection via the ip argument in the /ap_ip.cgi component.
CVE search metadata
CVE search record: CVE-2026-101072. Severity: critical. CVSS: 10.0. KEV: no. Product: NR289-GE (1.4.5102). Brief: Remote Command Injection in Netcore NR289-GE. Brief link: https://feed.craftedsignal.io/briefs/2026-09-netcore-cve/
What's new
A critical security vulnerability has been identified in the Netcore NR289-GE router, specifically in version 1.4.5102. The flaw resides within the CGI handler component, specifically the /ap_ip.cgi script. An unauthenticated remote attacker can inject arbitrary operating system commands by manipulating the 'ip' HTTP GET or POST parameter. Because the CGI handler processes this input without sufficient sanitization before passing it to a system shell, the vulnerability allows for full system compromise with the privileges of the web server process. The vendor has not responded to disclosure attempts, and proof-of-concept exploit code is publicly available, increasing the risk of exploitation by opportunistic threat actors targeting edge devices.
Impact
Successful exploitation of this vulnerability results in full remote control of the affected Netcore NR289-GE device. Potential impacts include unauthorized access to internal network traffic, lateral movement into the local network, and the deployment of persistent malware or backdoors on the gateway device. Given the critical 10.0 CVSS score, this vulnerability poses a severe risk to any organization utilizing these routers in internet-facing configurations.
Recommendation
Deploy network-level detection for the suspicious HTTP requests associated with this exploit. Since the vendor has not provided a patch, administrators should prioritize restricting access to the web management interface of the NR289-GE to trusted IP ranges only. If remote management is not required, disable the web management interface entirely until a vendor-supplied firmware update becomes available.
Immediate actions
Restrict access to /ap_ip.cgi on Netcore NR289-GE devices via ACLs
Threat Hunt
Search logs for requests to /ap_ip.cgi containing shell metacharacters
Data: Web server access logs
Mitigations
Disable external access to web management interface
CVE-2026-101072
Detection coverage 2
Detects CVE-2026-101072 Exploitation - OS Command Injection via /ap_ip.cgi
criticalDetects exploitation attempts against Netcore NR289-GE where the ip argument contains common shell injection characters.
Detects CVE-2026-101075 Exploitation - OS Command Injection via /location_time.cgi
criticalDetects exploitation attempts against CVE-2026-101075 by identifying shell metacharacters in the mac parameter of the /location_time.cgi endpoint
Detection queries are available on the platform. Get full rules →