天下漏洞,尽知其名
HIGH

CVE-2026-101188 Netcore POWER13 弱密码恢复漏洞

影响远程攻击者可重置设备密码,可能导致设备被完全控制

AI 研判

Netcore POWER13 路由器固件 2.0.240730.162638 版本中,/ubus 接口的 routerd.passwd_set 函数存在弱密码恢复漏洞。攻击者可远程利用该漏洞重置或恢复设备密码,且利用代码已公开。厂商已被告知但未作回应。

影响范围

Netcore POWER13

Netcore POWER13 固件版本 2.0.240730.162638 受影响,其他版本是否受影响暂无公开信息。

漏洞详情

该漏洞属于弱密码恢复机制缺陷,位于 /ubus 接口的 routerd.passwd_set 函数中。攻击者可通过构造特定请求远程触发密码重置流程,从而绕过正常认证获取设备控制权。由于利用方式已公开,攻击门槛较低。

利用条件与风险

攻击者可远程发起利用,无需物理接触设备,前提是目标设备的 /ubus 接口可被访问。鉴于利用代码已公开,实战中被扫描和攻击的风险较高。

修复建议

官方尚未发布修复方案,建议用户关注厂商更新;临时缓解措施包括限制 /ubus 接口的远程访问、关闭不必要的远程管理功能或部署防火墙规则进行访问控制。

原始情报

A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak password recovery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.