PT-2026-99914 · Netcore · Nr289-Ge
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Netcore NR289-GE version 1.4.5102
Description
An OS command injection flaw exists in the CGI Handler component. A remote attacker can exploit this by manipulating the
ntp ip argument within the /set ntp server ip.cgi endpoint, which affects the system function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
ntp ip argument in the /set ntp server ip.cgi endpoint to minimize the risk of exploitation.Exploit
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nr289-Ge