NR289-GE vulnerabilities
CVEs whose affected-version data names the NR289-GE package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2026-101076Critical· 10.0Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The att…
CVE-2026-101077Critical· 10.0PoCNetcore NR289-GE boa_temp process_request missing authentication
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The expl…
CVE-2026-101073High· 8.3A security flaw has been discovered in Netcore NR289-GE 1.4.5102
A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initi…
CVE-2026-101074Critical· 9.8PoCA weakness has been identified in Netcore NR289-GE 1.4.5102
A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-ba…
CVE-2026-101075Critical· 10.0A security vulnerability has been detected in Netcore NR289-GE 1.4.5102
A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os …
CVE-2026-101072Critical· 10.0PoCA vulnerability was identified in Netcore NR289-GE 1.4.5102
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can b…