Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-101075: Netcore NR289-GE allows remote command injection

CVE-2026-101075 · published 4 days ago
Summary

The NR289-GE video intercom running version 1.4.5102 can be tricked into executing operating system commands when an attacker supplies a crafted MAC address to its location_time.cgi feature. This means a remote attacker could take control of the device and potentially access the internal network. Update the firmware to a patched version or disable the affected function until a fix is applied.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
netcore nr289-ge 1.4.5102
Original advisory text
Netcore NR289-GE Location Time location_time.cgi system os command injection
A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
2% chance of attack within 30 days
Type
CWE-77Command Injection
CWE-78OS Command Injection
Timeline
Published28 Sep 2026
Updated30 Sep 2026
First seen28 Sep 2026
Sources
CVE-2026-101075 · MITRE
Track software like this
Free during beta