Remote Code Execution Vulnerability in Netcore NAP930 Backup/Restore Functionality
CVE-2026-102241
Key Information:
Badges
What is CVE-2026-102241?
A critical security issue has been identified within the Netcore NAP930 product, specifically in the Backup/Restore component. The vulnerability allows for the exploitation of an unknown portion of code in the '/lib/functions/backup_common.sh' file. The flaw arises due to improper handling of the 'aes_pass' argument, which leads to the use of a hard-coded cryptographic key. This situation enables attackers to potentially initiate remote attacks, leveraging disclosed exploit techniques. Despite early notification efforts directed at the vendor regarding this vulnerability, no feedback or remediation steps have been provided.
Affected Version(s)
NAP930 0.1.241010.141410
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
