MEDIUM
Netcore NR289-GE CGI Dispatcher boa improper authentication
Published Sep 28, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.63%
Description
A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 1.4.5102StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88293 Advisory
- https://github.com/senxitoyshuyi-ui/HACKALL/blob/main/netcore_NR289-GE_V1.4.5102%2C2018.06.1418_44%20Router/Netcore_NR289-GE_authentication_bypass.md exploit
- https://vuldb.com/cve/CVE-2026-101073 third-party-advisory
- https://vuldb.com/submit/929197 third-party-advisory
- https://vuldb.com/vuln/410944 vdb-entry
- https://vuldb.com/vuln/410944/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88293 | Advisory | |
| https://github.com/senxitoyshuyi-ui/HACKALL/blob/main/netcore_NR289-GE_V1.4.5102%2C2018.06.1418_44%20Router/Netcore_NR289-GE_authentication_bypass.md | exploit | |
| https://vuldb.com/cve/CVE-2026-101073 | third-party-advisory | |
| https://vuldb.com/submit/929197 | third-party-advisory | |
| https://vuldb.com/vuln/410944 | vdb-entry | |
| https://vuldb.com/vuln/410944/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 28, 2026
Updated Oct 1, 2026
Reserved Sep 27, 2026
Link CVE-2026-101073
CISA Vulnrichment
Updated Oct 1, 2026
ENISA EUVD
EUVD-2026-88293 Assigner VulDB
Published Sep 28, 2026
Updated Oct 1, 2026
Exploited since n/a
Link EUVD-2026-88293