在 Netcore NR289-GE 设备(版本 1.4.5102)中发现了一个漏洞。该问题影响 文件中 CGI 处理组件的 函数。通过对 参数的恶意操纵,可触发操作系统命令注入漏洞。该攻击可远程发起。漏洞利用代码已在公开渠道发布,存在被滥用的风险。厂商在早期曾就此披露信息被联系,但始终未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101001 | 10.0 CRITICAL | Netcore NBR200V2 Web Management network_tools eval os command injection |
| CVE-2026-101000 | 10.0 CRITICAL | Netcore NBR100V2 ACL unauthenticated.json uci.apply authorization |
| CVE-2026-101002 | 9.9 CRITICAL | Netcore NBR200V2 Tools Ping network_tools system os command injection |
| CVE-2026-101074 | 9.8 CRITICAL | Netcore NR289-GE Authentication boa password-check stack-based overflow |
| CVE-2026-101073 | 8.3 HIGH | Netcore NR289-GE CGI Dispatcher boa improper authentication |
No comments yet