Cyber & AI intelligence
Wasteland.
Briefs indexed2924
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-101077 2026-09-28

CVE-2026-101077: Unauthenticated Access Flaw in Netcore NR289-GE Router boa_temp Handler

"A critical missing-authentication flaw in the Netcore NR289-GE router's `boa_temp` handler can be exploited remotely without credentials, a public exploit exists, and the vendor has not responded to the disclosure."

A critical missing-authentication flaw in the Netcore NR289-GE router's boa_temp handler can be exploited remotely without credentials, a public exploit exists, and the vendor has not responded to the disclosure.

What Is It

CVE-2026-101077 is a flaw in the process_request function of the boa_temp Handler component in Netcore NR289-GE firmware version 1.4.5102. According to the NVD description, the flaw causes missing authentication and can be exploited remotely. The weakness is classified as CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function).

The public researcher write-up linked in the NVD references is titled "Netcore_NR289-GE_unauth_file_write," which points to an unauthenticated file write.

VulDB, acting as the CNA, published the CVE on September 28, 2026. NVD lists the record's status as "Deferred."

Why It Matters

The CNA rated this flaw at the top of the severity scale:

The vectors show an attacker can reach the flaw over the network with low complexity, no privileges and no user interaction. Impact to confidentiality, integrity and availability is high, and the 3.1 score has a changed scope.

CISA's SSVC assessment as Coordinator lists exploitation as PoC, automatable as yes, and technical impact as total. The NVD description also says the exploit "has been published and may be used."

KEV status: The supplied CISA KEV data contains no entry for this CVE. Active exploitation in the wild is not confirmed by KEV at this time.

What's Vulnerable

The supplied records name no other affected versions.

Patch Status

The supplied sources list no patch or vendor advisory. According to the NVD description, the vendor was contacted early about the disclosure but "did not respond in any way." There is no CISA KEV required action because the CVE is not in the KEV catalog.

Organizations running NR289-GE 1.4.5102 should treat these devices as unpatched and exposed to a flaw with a public proof-of-concept.

Sources