VYPR

NR289-GE

by Netcore

CVEs (6)

  • CVE-2026-101077CriSep 28, 2026
    risk 0.65cvss 10.0epss —

    A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used.…

  • CVE-2026-101076CriSep 28, 2026
    risk 0.65cvss 10.0epss —

    A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit…

  • CVE-2026-101075CriSep 28, 2026
    risk 0.65cvss 10.0epss —

    A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of…

  • CVE-2026-101072CriSep 28, 2026
    risk 0.65cvss 10.0epss —

    A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is…

  • CVE-2026-101074CriSep 28, 2026
    risk 0.64cvss 9.8epss —

    A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be…

  • CVE-2026-101073HigSep 28, 2026
    risk 0.54cvss 8.3epss —

    A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been…