CVE-2026-101072: Netcore NR289-GE CGI ap_ip.cgi system os command injection
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /apip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker can launch the attack remotely without authentication or user interaction. Exploitation involves manipulating the ip argument passed to /ap_ip.cgi.
How serious is successful exploitation?
Successful exploitation can result in operating-system command injection, with high impact to confidentiality, integrity, and availability. A public exploit is available, increasing the likelihood of exploitation attempts.
Is a vendor fix available?
The available information does not identify a fix or workaround. The vendor was contacted before disclosure but did not provide a response.