CVE-2026-101072 is a critical OS command injection flaw in the CGI handler of the Netcore NR289-GE router, version 1.4.5102, that can be exploited remotely without authentication; a public exploit exists and the vendor has not responded to disclosure.
What Is It
The flaw is in the system function of /ap_ip.cgi, which belongs to the router's CGI Handler component. An attacker who manipulates the ip argument can inject operating system commands. The weakness is classified as CWE-77 (Command Injection) and CWE-78 (OS Command Injection).
VulDB, acting as the CNA, published the record on 2026-09-28. Its NVD status is currently "Deferred."
Why It Matters
The CVSS scores are at or near the maximum:
- CVSS 3.1: 10.0 CRITICAL (
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) - CVSS 4.0: 9.3 CRITICAL, with exploit maturity rated Proof-of-Concept
- CVSS 2.0: 10.0
The attack works over the network with low complexity. It needs no privileges and no user interaction. According to the CVE description, "the exploit is publicly available and might be used." CISA's SSVC assessment rates exploitation as poc, automatable as yes, and technical impact as total.
The supplied data has no CISA KEV entry for this CVE, so active exploitation in the wild is not confirmed at this time. Still, the combination of a public exploit, no authentication, automatability, and total technical impact makes exposed devices high-value targets.
What's Vulnerable
- Vendor: Netcore
- Product: NR289-GE
- Affected version: 1.4.5102
- Component: CGI Handler (
/ap_ip.cgi) - CPE:
cpe:2.3:a:netcore:nr289-ge:*:*:*:*:*:*:*:*
The source records list no other affected versions.
Patch Status
The source data lists no patch or vendor advisory. According to the CVE description, the vendor "was contacted early about this disclosure but did not respond in any way." Since there is no CISA KEV entry, there is also no federal required action or due date.
Until the vendor provides a fix, organizations running the NR289-GE on firmware 1.4.5102 should treat these devices as unpatched and exposed to a critical, remotely exploitable flaw.