CVE-2026-101077 Netcore NR289-GE 认证缺失漏洞
影响远程攻击者可未授权访问并可能控制设备
Netcore NR289-GE 路由器固件 1.4.5102 中,boa_temp Handler 组件的 process_request 函数存在认证缺失漏洞。该漏洞可被远程利用,且利用代码已公开,厂商未作回应。
影响范围
Netcore NR289-GE 固件版本 1.4.5102 受影响,其他版本是否受影响暂无公开信息。
漏洞详情
漏洞类型为认证缺失(Missing Authentication)。由于 boa_temp Handler 的 process_request 函数未正确校验请求身份,攻击者可直接发送特制请求绕过认证。远程攻击者无需登录即可触发,且已有公开利用方式。
利用条件与风险
利用前提为设备网络可达,无需认证。鉴于 CVSS 10 且利用代码已公开,实战风险极高,可能导致设备被完全控制。
修复建议
官方尚未发布修复方案,建议关注厂商更新;临时缓解可限制设备管理接口的公网访问,或部署防火墙/访问控制策略。
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.