CRITICAL
Netcore NR289-GE CGI ap_ip.cgi system os command injection
Published Sep 28, 2026
10.0
CRITICALCVSS 4.0
EPSS 1.99%
Description
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 1.4.5102StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://github.com/senxitoyshuyi-ui/HACKALL/blob/main/netcore_NR289-GE_V1.4.5102%2C2018.06.1418_44%20Router/Netcore_NR289-GE_ap_ip_command_injection.md exploit
- https://vuldb.com/cve/CVE-2026-101072 third-party-advisory
- https://vuldb.com/submit/929176 third-party-advisory
- https://vuldb.com/vuln/410943 vdb-entrytechnical-description
- https://vuldb.com/vuln/410943/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://github.com/senxitoyshuyi-ui/HACKALL/blob/main/netcore_NR289-GE_V1.4.5102%2C2018.06.1418_44%20Router/Netcore_NR289-GE_ap_ip_command_injection.md | exploit | |
| https://vuldb.com/cve/CVE-2026-101072 | third-party-advisory | |
| https://vuldb.com/submit/929176 | third-party-advisory | |
| https://vuldb.com/vuln/410943 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/410943/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 28, 2026
Updated Sep 28, 2026
Reserved Sep 27, 2026
Link CVE-2026-101072
CISA Vulnrichment
Updated Sep 28, 2026