---
id: CVE-2026-102241
title: A vulnerability was determined in Netcore NAP930 0.1.241010.141410
summary: >-
  A vulnerability was determined in Netcore NAP930 0.1.241010.141410. This
  vulnerability affects unknown code of the file /lib/functions/backup_common.sh
  of the component Backup/Restore. This manipulation of the argument aes_pass
  causes us…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-320
  - CWE-321
vendor: Netcore
product: NAP930
affected:
  - NAP930 0.1.241010.141410
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T03:17:14.510'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102241'
references:
  - url: >-
      https://github.com/senxitoyshuyi-ui/HACKALL/blob/main/netcore_NAP930%20V0.1.241010.141410%20Router/NAP930_backup_hardcoded_aes_key.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-102241'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/931269'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/411140'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/411140/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T03:26:23.051Z'
---

## Overview

A vulnerability was determined in Netcore NAP930 0.1.241010.141410. This vulnerability affects unknown code of the file /lib/functions/backup_common.sh of the component Backup/Restore. This manipulation of the argument aes_pass causes use of hard-coded cryptographic key . It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
