VYPR
Vypr IntelligenceAI-generatedSep 29, 2026· 12 CVEs

Netcore: Twelve Vulnerabilities Including Critical Command Injection Disclosed Together

A batch of twelve vulnerabilities, including critical command injection and authentication bypass flaws, were disclosed for Netcore devices from September 28-29, 2026.

Key findings

  • Twelve vulnerabilities disclosed for Netcore devices between September 28-29, 2026, with a focus on critical command injection and auth bypass flaws.
  • Multiple Netcore models including NR289-GE, NBR200V2, NBR100V2, NAP930, and POWER13 are affected by this batch.
  • Several critical flaws allow for remote OS command injection, with exploits publicly available for many.
  • Authentication bypass and weak password recovery vulnerabilities were also disclosed, increasing remote attack vectors.
  • Affected versions range from Netcore NAP930 0.1.241010.141410 to NR289-GE 1.4.5102, highlighting the need for broad patching.

On September 28-29, 2026, a batch of twelve vulnerabilities was disclosed across multiple Netcore device models, with a significant cluster of critical and high-severity flaws impacting remote command injection and authentication bypass. The vulnerabilities were disclosed within a 22-hour window, highlighting a concentrated disclosure event by security researchers. These findings underscore the importance of timely patching for Netcore devices to mitigate risks associated with remote exploitation.

Several critical vulnerabilities revolve around OS command injection, affecting various Netcore models. The NR289-GE (1.4.5102) is impacted by CVE-2026-101075 and CVE-2026-101076, both exploiting the 'system' function in CGI handlers (/location_time.cgi and /set_ntp_server_ip.cgi respectively) via manipulation of 'mac' and 'ntp_ip' arguments. Another critical command injection flaw, CVE-2026-101072, affects the NR289-GE (1.4.5102) via its 'ap_ip.cgi' script, manipulating the 'ip' argument. The NAP930 (0.1.241010.141410) also suffers from command injection in its Network Tools CGI component, specifically CVE-2026-102240, which targets the 'eval' function in '/www/cgi-bin/network_tools' by manipulating the 'sid' argument. Furthermore, the NBR200V2 (1.3.241127.071246) has CVE-2026-101001, a critical command injection vulnerability in its web management interface, exploiting the 'eval' function via the 'QUERY_STRING' argument. The NBR200V2 also faces CVE-2026-101002, where command injection is possible through the 'network_tools' component by manipulating the 'url' argument.

Authentication bypass and related issues form another significant theme within this batch. CVE-2026-101000, a critical vulnerability in the NBR100V2 (1.3.240614.030928), involves missing authorization due to manipulation of the 'section' argument in the 'uci.apply' function within an ACL handler. The NR289-GE (1.4.5102) is affected by CVE-2026-101073, an improper authentication flaw in its CGI dispatcher, and CVE-2026-101074, a critical stack-based buffer overflow vulnerability in its authentication component ('password-check' function in '/bin/boa') due to Username manipulation. Additionally, the POWER13 (2.0.240730.162638) has CVE-2026-101188, a high-severity vulnerability allowing weak password recovery via the 'routerd.passwd_set' function.

The batch also includes a low-severity vulnerability, CVE-2026-102241, affecting Netcore NAP930 (0.1.241010.141410). This flaw involves the use of a hard-coded cryptographic key in the 'backup_common.sh' script within the Backup/Restore component, stemming from the manipulation of the 'aes_pass' argument.

Exploitation context is provided for several critical vulnerabilities. CVE-2026-102240, CVE-2026-101188, CVE-2026-101077, CVE-2026-101076, CVE-2026-101074, CVE-2026-101073, CVE-2026-101072, CVE-2026-101002, CVE-2026-101001, and CVE-2026-101000 are all noted as having publicly available exploits, with some potentially being used for attacks. The related news coverage specifically mentions that CVE-2026-101000, CVE-2026-101001, and CVE-2026-101002 were disclosed within a single hour, indicating a concentrated release.

Affected versions are explicitly mentioned for some of the vulnerabilities. The NR289-GE is affected at version 1.4.5102, the NBR200V2 at 1.3.241127.071246, and the NBR100V2 at 1.3.240614.030928. The NAP930 is affected at version 0.1.241010.141410, and the POWER13 at 2.0.240730.162638. Specific patch information or fixed versions were not detailed in the provided data for this batch.

Users of Netcore devices are urged to review the specific models and versions affected by these vulnerabilities. The prevalence of critical command injection and authentication bypass flaws, coupled with the availability of exploits, necessitates prompt attention to security updates and device configurations to prevent potential remote takeovers and data breaches. The concentrated nature of this disclosure event suggests a coordinated effort to reveal multiple security weaknesses in Netcore products.

AI-written article. Grounded in 12 CVE records listed below.