Skip to finding
important · Firmware

A LAN peer can bypass the Netcore NR289-GE web login and execute commands as root.

Affects

Netcore NR289-GE, an embedded SMB router and wireless access-point controller.

Placing .ico before a CGI path bypasses both Boa and CGI permission checks, exposing handlers that interpolate form values into root shell commands.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026