天下漏洞,尽知其名
HIGH

CVE-2026-101073 Netcore NR289-GE 认证不当漏洞

影响攻击者可远程绕过认证访问设备功能

AI 研判

Netcore NR289-GE 路由器固件 1.4.5102 的 /bin/boa 组件(CGI Dispatcher)中存在认证不当漏洞。攻击者可远程利用该缺陷绕过身份验证,且公开利用代码已发布,厂商未作回应。

影响范围

Netcore NR289-GE

Netcore NR289-GE 固件版本 1.4.5102,其他版本是否受影响暂无公开信息。

漏洞详情

漏洞位于设备 Web 服务程序 /bin/boa 的 CGI 分发处理逻辑中,属于认证不当(Improper Authentication)类型。由于对请求的身份校验不充分,攻击者可通过构造特定 HTTP 请求绕过登录验证,直接访问受保护的 CGI 接口。该漏洞可远程触发,无需本地接触设备。

利用条件与风险

利用前提是设备 Web 管理界面可被网络访问,攻击者无需有效凭据即可尝试利用。由于公开 PoC 已存在且厂商未响应,实际被扫描和攻击的风险较高。

修复建议

官方暂未发布修复方案,建议限制设备管理界面的网络暴露(仅内网或白名单访问)、关闭远程管理功能,并关注厂商后续公告。

原始情报

A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.