CVE-2026-101075 Netcore NR289-GE 命令注入漏洞
影响攻击者可远程执行任意系统命令
Netcore NR289-GE 1.4.5102 的 Location Time Handler 组件中,/location_time.cgi 文件的 system 函数在处理 mac 参数时未做充分过滤,导致操作系统命令注入。该漏洞可被远程利用,且利用代码已公开,厂商未作回应。
影响范围
Netcore NR289-GE 1.4.5102(其他版本是否受影响暂无公开信息)
漏洞详情
漏洞类型为操作系统命令注入。程序将用户可控的 mac 参数直接拼接进 system 调用中执行,攻击者通过构造恶意 mac 值即可注入并执行任意系统命令。该接口可被远程访问,无需本地接触设备。
利用条件与风险
利用前提是目标设备的 /location_time.cgi 接口可被远程访问,且无需认证或认证可绕过(具体条件暂无公开信息)。由于 PoC 已公开且 CVSS 为 10,实战风险极高,可能导致设备被完全控制。
修复建议
官方暂未发布修复方案,厂商未回应。临时缓解措施包括:限制该 CGI 接口的远程访问、在边界设备上过滤恶意请求,或将该设备置于隔离网络并监控异常命令执行。
A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.