<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>NR289-GE (1.4.5102) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/nr289-ge-1.4.5102/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 16:20:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/nr289-ge-1.4.5102/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection in Netcore NR289-GE</title><link>https://feed.craftedsignal.io/briefs/2026-09-netcore-cve/</link><pubDate>Mon, 28 Sep 2026 16:20:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-netcore-cve/</guid><description>Netcore NR289-GE version 1.4.5102 is vulnerable to remote unauthenticated OS command injection via the ip argument in the /ap_ip.cgi component.</description><content:encoded><![CDATA[<p>A critical security vulnerability has been identified in the Netcore NR289-GE router, specifically in version 1.4.5102. The flaw resides within the CGI handler component, specifically the /ap_ip.cgi script. An unauthenticated remote attacker can inject arbitrary operating system commands by manipulating the 'ip' HTTP GET or POST parameter. Because the CGI handler processes this input without sufficient sanitization before passing it to a system shell, the vulnerability allows for full system compromise with the privileges of the web server process. The vendor has not responded to disclosure attempts, and proof-of-concept exploit code is publicly available, increasing the risk of exploitation by opportunistic threat actors targeting edge devices.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in full remote control of the affected Netcore NR289-GE device. Potential impacts include unauthorized access to internal network traffic, lateral movement into the local network, and the deployment of persistent malware or backdoors on the gateway device. Given the critical 10.0 CVSS score, this vulnerability poses a severe risk to any organization utilizing these routers in internet-facing configurations.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Deploy network-level detection for the suspicious HTTP requests associated with this exploit. Since the vendor has not provided a patch, administrators should prioritize restricting access to the web management interface of the NR289-GE to trusted IP ranges only. If remote management is not required, disable the web management interface entirely until a vendor-supplied firmware update becomes available.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>cve</category><category>remote-code-execution</category><category>network-device</category><category>edge-security</category></item></channel></rss>