Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-101076: Netcore NR289‑GE allows remote command execution via NTP setting
CVE-2026-101076 · published 12 days ago
Summary
The Netcore NR289‑GE device (firmware version 1.4.5102) lets an attacker send specially crafted data to the NTP configuration page, causing the system to run arbitrary commands. This can be done from anywhere on the network and could let a malicious user take control of the device. Apply the vendor’s security update or disable the vulnerable CGI function until a patch is available.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| netcore | nr289-ge | 1.4.5102 |
Original advisory text
Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-78OS Command Injection
CWE-77Command Injection
Timeline
Published28 Sep 2026
Updated7 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta