Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-101075: Netcore NR289-GE allows remote command injection
CVE-2026-101075 · published 4 days ago
Summary
The NR289-GE video intercom running version 1.4.5102 can be tricked into executing operating system commands when an attacker supplies a crafted MAC address to its location_time.cgi feature. This means a remote attacker could take control of the device and potentially access the internal network. Update the firmware to a patched version or disable the affected function until a fix is applied.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| netcore | nr289-ge | 1.4.5102 |
Original advisory text
Netcore NR289-GE Location Time location_time.cgi system os command injection
A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-77Command Injection
CWE-78OS Command Injection
Timeline
Published28 Sep 2026
Updated30 Sep 2026
First seen28 Sep 2026
Track software like this
Free during beta