Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-101072: Netcore NR289-GE allows remote command execution via ap_ip.cgi

CVE-2026-101072 · published 12 days ago
Summary

The Netcore NR289-GE device (version 1.4.5102) runs a web script called ap_ip.cgi that accepts an IP address parameter. By sending a specially crafted value, an attacker can cause the device to run any command it wants, potentially taking control of the equipment. Apply the latest firmware from the vendor or block external access to that script to protect your system.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
netcore nr289-ge 1.4.5102
Original advisory text
Netcore NR289-GE CGI ap_ip.cgi system os command injection
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
2% chance of attack within 30 days
Type
CWE-77Command Injection
CWE-78OS Command Injection
Timeline
Published28 Sep 2026
Updated7 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-101072 · MITRE
Track software like this
Free during beta