天下漏洞,尽知其名
CRITICAL

CVE-2026-101074 Netcore NR289-GE 堆栈缓冲区溢出漏洞

影响攻击者可远程触发栈溢出,可能导致任意代码执行或设备崩溃

AI 研判

Netcore NR289-GE 路由器固件 1.4.5102 的认证组件存在栈缓冲区溢出漏洞。问题位于 /bin/boa 中的 password-check 函数,对 Username 参数处理不当。该漏洞已有公开利用代码,且厂商未作回应。

影响范围

Netcore NR289-GE

Netcore NR289-GE 固件版本 1.4.5102。其他版本是否受影响暂无公开信息。

漏洞详情

漏洞类型为栈缓冲区溢出(CWE-121)。/bin/boa 的 password-check 函数在处理登录请求中的 Username 参数时未做长度校验,超长输入可覆盖栈上数据。攻击者可远程构造恶意请求触发溢出,进而劫持程序执行流。

利用条件与风险

攻击者可远程发起利用,无需认证即可触发,且公开 PoC 已存在,实战风险高。成功利用可能导致设备被完全控制或拒绝服务。

修复建议

官方尚未发布修复补丁,建议关注厂商公告。临时缓解措施包括限制设备管理接口的访问来源、关闭不必要的远程管理功能,或部署网络层防护过滤异常请求。

原始情报

A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.