External risk intelligence

Netcore NR289-GE Location Time Handler OS Command Injection

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-101075

This vulnerability affects a router, which is a network device commonly exposed to the internet. The vulnerable component, a CGI script, functions as an external gateway or management interface reachable via the network, making internet-facing exposure a common deployment pattern for this type of consumer networking equipment.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been discovered in Netcore routers, specifically in a component that handles location and time settings. This issue allows for remote exploitation, meaning attackers could potentially execute commands on the affected devices without needing direct access or any authentication. The vendor has not responded to the disclosure of this vulnerability.

  • Attackers can remotely run commands on routers.
  • Network devices are often internet-exposed.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can reach the vulnerable system remotely and manipulate the `mac` argument within the `/location_time.cgi` file. This targeted manipulation allows the attacker to inject operating system commands, potentially leading to significant compromise.

  • No special access required.
  • Manipulate `mac` argument in `/location_time.cgi`.
  • Leads to OS command injection.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the Location Time Handler component could allow an unauthenticated remote attacker to execute arbitrary commands on the affected system by manipulating the 'mac' argument in the `/location_time.cgi` file. This could lead to a full compromise of the device when supported by the advisory.

  • Device command execution.
  • Remote, unauthenticated access.
  • Complete system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given this vulnerability affects a router, network and security teams are likely responsible for identifying affected devices and assessing exposure. The first practical step is to inventory all deployed routers, confirm their external reachability, and determine their business criticality. Once identified, the accountable owner for each affected router should be confirmed, and a remediation plan should be developed based on the assessed risk and available maintenance windows.

  • Identify affected router inventory.
  • Verify external reachability and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Netcore NR289-GE router?

The Netcore NR289-GE is a consumer networking device. It functions as a router to manage internet connectivity and local network traffic. The affected component, the Location Time Handler, is a system feature within the device's management interface responsible for syncing time and location settings.

What does OS command injection mean for CVE-2026-101075?

This vulnerability is categorized as OS command injection, which falls under CWE-77 and CWE-78. It means an attacker can provide specially crafted input to the device that the system inadvertently executes as a system-level command. By exploiting this flaw, an attacker gains the ability to run unauthorized operations directly on the router's operating system.

How is this vulnerability triggered?

An attacker triggers this flaw by sending a specific request to the /location_time.cgi file on the router. By manipulating the 'mac' argument in that request, they can inject malicious commands. Importantly, this does not require the attacker to have prior authentication or special user privileges; the request is processed directly by the device's handler.

Should I be concerned about CVE-2026-101075?

Yes, if you manage these devices. According to Halo Surface Signal, this vulnerability is considered a likely risk because the affected CGI script acts as an interface typically reachable over the network. Because these routers are often deployed with their management interfaces exposed to the internet, remote attackers may be able to reach the vulnerable component without needing internal network access.

What should I do if I use this router?

Your first step is to locate all Netcore NR289-GE devices within your network inventory. Determine which of these devices are accessible from the internet and evaluate their role in your environment. Once you have an accurate list, assign owners to those units to plan further risk management or mitigation, as the vendor has not provided an official fix.

References