External risk intelligence

Netcore NR289-GE Missing Authentication Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-101077

The affected product is a router. Routers are designed as internet edge devices, and vulnerabilities in their web management or request handling components are typically exposed directly to the public internet by design in normal deployment scenarios.

Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been discovered in Netcore routers that could allow remote attackers to bypass authentication. The issue resides within the request processing function of the boa_temp Handler component. An exploit for this vulnerability has been published, and the vendor has not responded to disclosures.

  • Missing authentication flaw in router.
  • Exploit is public; vendor unresponsive.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can remotely reach the affected router and trigger a vulnerability by sending a specially crafted request to the vulnerable component. This leads to a bypass of authentication, potentially allowing further compromise.

  • Requires network access.
  • Triggers missing authentication in request handling.
  • Enables remote compromise of the device.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated, remote attacker to bypass access controls in the Netcore NR289-GE router. When supported by the advisory, this could lead to unauthorized manipulation of system functions.

  • Router access controls could be bypassed.
  • Remote unauthenticated access could occur.
  • Unauthorized system access may result.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Netcore NR289-GE router's web interface is a likely target for this unauthenticated remote attack, placing responsibility on network or security teams to manage edge devices. The first step is to confirm the presence and reachability of these routers, identify their owners, and then prioritize remediation based on business criticality and exposure.

  • Own the issue: Network and security teams.
  • Verify first: Device presence and internet reachability.
  • Action: Plan vendor engagement or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Netcore NR289-GE router?

The Netcore NR289-GE is a networking device typically used to manage local area network traffic and provide internet connectivity. It functions as a gateway, often hosting an internal web-based management interface that allows administrators to configure network settings, security policies, and device behavior through a browser-based handler.

What does this missing authentication vulnerability mean?

This flaw, classified under CWE-287 and CWE-306, means the device fails to properly verify the identity of a user before granting access to protected functions. In CVE-2026-101077, the boa_temp Handler improperly processes incoming requests, allowing remote attackers to interact with the device's management features without needing to provide a valid username or password.

How can an attacker trigger this CVE-2026-101077 vulnerability?

An attacker triggers this by sending a specially crafted, malicious request over the network directly to the vulnerable boa_temp Handler component. It does not require any prior local access, valid user credentials, or social engineering to activate; however, the vulnerability is not triggered if the device's management interface is entirely isolated from the network being targeted.

How do I know if my device is at risk?

According to Halo Surface Signal, routers are designed as internet edge devices, making them highly likely to be exposed to the public internet by design. If your specific Netcore NR289-GE unit is reachable from the outside world, it is considered at higher risk because the management interface, which hosts the vulnerable handler, is directly accessible to external parties.

What is the first step to take for this router issue?

Begin by identifying all Netcore NR289-GE devices currently active on your network and verifying whether their management interfaces are accessible from the internet. Since there is no vendor response for this, prioritize isolating these devices from external networks and evaluate replacing them, as the lack of a patch leaves the authentication bypass fully functional.

References