CRITICAL 9.3 NVD

CVE-2026-101072

A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such ma

A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

References

Published: 2026-09-28 · Source: NVD · Feed updated: 2026-09-28
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-28 via NVD.

Risk Timeline

CVE Disclosed2026-09-28 · -1 days ago

Remediation Resources

vulnfeed aggregates 13625 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.