A public exploit is available for a CVSS 10.0 OS command injection flaw in the NTP configuration handler of Netcore NR289-GE firmware 1.4.5102. The vendor has not responded to the disclosure.
What Is It
CVE-2026-101076 is an OS command injection vulnerability (CWE-77, CWE-78) in the CGI Handler component of the Netcore NR289-GE router. The flaw is in the system function, which is reached through /set_ntp_server_ip.cgi. An attacker can inject operating system commands by manipulating the ntp_ip argument. VulDB assigned the CVE, and it was published to NVD on September 28, 2026. NVD currently lists its status as "Deferred."
Why It Matters
The vulnerability has the highest possible CVSS v3.1 score:
- CVSS 3.1: 10.0 CRITICAL (
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) - CVSS 4.0: 9.3 CRITICAL, with exploit maturity rated Proof-of-Concept
- CVSS 2.0: 10.0
An attacker can launch the attack remotely. It has low complexity and requires no privileges or user interaction. Because the scope is changed, an exploited device can affect resources beyond the vulnerable component, with high impact to confidentiality, integrity and availability.
The CVE description says the exploit has been disclosed to the public and may be used. A proof-of-concept write-up is posted on GitHub. None of the sources cited here reports active exploitation in the wild. This brief did not check the CISA Known Exploited Vulnerabilities (KEV) catalog, so it makes no claim about whether the CVE is listed there.
What's Vulnerable
- Vendor: Netcore
- Product: NR289-GE
- Affected version: 1.4.5102
- Component: CGI Handler (
/set_ntp_server_ip.cgi, parameterntp_ip)
The cited sources list no other affected versions.
Patch Status
The cited sources do not identify a fix. According to the CVE record, the reporter contacted Netcore early about this disclosure, but the vendor "did not respond in any way." Organizations covered by BOD 22-01 should check the CISA KEV catalog directly to see whether a federal required action or due date applies.
Owners of NR289-GE devices running firmware 1.4.5102 should assume no vendor patch is coming soon. Do not expose these devices' management interfaces to untrusted networks.