天下漏洞,尽知其名
CRITICAL

CVE-2026-101072 Netcore NR289-GE 命令注入漏洞

影响攻击者可远程执行任意操作系统命令

AI 研判

Netcore NR289-GE 路由器 1.4.5102 版本中,CGI 处理组件 /ap_ip.cgi 的 system 函数对 ip 参数未做充分过滤,导致操作系统命令注入。该漏洞可远程触发,且利用代码已公开,厂商未作回应。

影响范围

Netcore NR289-GE

Netcore NR289-GE 1.4.5102 版本受影响,其他版本是否受影响暂无公开信息。

漏洞详情

漏洞类型为操作系统命令注入。CGI 脚本 /ap_ip.cgi 在处理 ip 参数时直接将其拼接到 system 调用中,未过滤 shell 元字符,攻击者可通过构造恶意 ip 值注入并执行任意系统命令。

利用条件与风险

攻击者可远程发起利用,无需认证或仅需低权限即可触发,利用代码已公开,实战风险极高。

修复建议

官方暂未发布修复方案,建议关注厂商公告;临时缓解可限制对 /ap_ip.cgi 的访问、过滤 ip 参数中的特殊字符或停用相关 CGI 接口。

原始情报

A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.