Netcore NR289-GE 1.4.510 版本中存在一个弱点。受影响的是 Authentication 组件中 /bin/boa 文件的 password-check 函数。通过操纵 Username 参数,可触发基于栈的缓冲区溢出漏洞。该漏洞可被远程利用,且相关利用代码已公开,可能被用于实施攻击。厂商早在披露初期即已被告知,但始终未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101001 | 10.0 CRITICAL | Netcore NBR200V2 Web Management network_tools eval os command injection |
| CVE-2026-101000 | 10.0 CRITICAL | Netcore NBR100V2 ACL unauthenticated.json uci.apply authorization |
| CVE-2026-101072 | 10.0 CRITICAL | Netcore NR289-GE CGI ap_ip.cgi system os command injection |
| CVE-2026-101075 | 10.0 CRITICAL | Netcore NR289-GE Location Time location_time.cgi system os command injection |
| CVE-2026-101002 | 9.9 CRITICAL | Netcore NBR200V2 Tools Ping network_tools system os command injection |
| CVE-2026-101073 | 8.3 HIGH | Netcore NR289-GE CGI Dispatcher boa improper authentication |
No comments yet