CVE-2026-102241: Netcore NAP930 Backup/Restore backup_common.sh hard-coded key
A vulnerability was determined in Netcore NAP930 0.1.241010.141410. This vulnerability affects unknown code of the file /lib/functions/backupcommon.sh of the component Backup/Restore. This manipulation of the argument aespass causes use of hard-coded cryptographic key . It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is described as remotely exploitable with low attack complexity, but it requires high privileges. No user interaction is required.
Which deployments are known to be affected?
The affected product is Netcore NAP930 version 0.1.241010.141410. The issue is associated with the Backup/Restore component and the /lib/functions/backup_common.sh file.
Is there evidence that exploitation is practical?
A public exploit disclosure exists and may be used. The available information also states that the vendor did not respond to early contact regarding the disclosure.