Missing Authentication Flaw in Netcore NR289-GE Router
CVE-2026-101077
Key Information:
Badges
What is CVE-2026-101077?
A vulnerability exists in the Netcore NR289-GE router where the boa_temp Handler's process_request function lacks adequate authentication. This flaw allows a remote attacker to exploit the system without authorization. The potential for exploitation has been made public, and despite early notifications to the vendor regarding this issue, no response has been received. Users should be cautious and consider implementing necessary security measures to protect their devices.
Affected Version(s)
NR289-GE 1.4.5102
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
