important · Firmware
A LAN peer can bypass the Netcore NR289-GE web login and execute commands as root.
Affects
Netcore NR289-GE, an embedded SMB router and wireless access-point controller.
Placing .ico before a CGI path bypasses both Boa and CGI permission checks, exposing handlers that interpolate form values into root shell commands.
Detail and 3 sources
The researcher demonstrated root command execution against extracted firmware under QEMU.
The path is normally limited to LAN management reachability, and no vendor patch has been identified.
Sources
Code / PoCHACKALL/netcore_NR289-GE_V1.4.5102,2018.06.1418_44 Router/Netcore_NR289-GE_authentication_bypass.md at main · senxitoyshuyi-ui/HACKALL · GitHubCode / PoCHACKALL/netcore_NR289-GE_V1.4.5102,2018.06.1418_44 Router/Netcore_NR289-GE_ap_ip_command_injection.md at main · senxitoyshuyi-ui/HACKALL · GitHubCode / PoCHACKALL/netcore_NR289-GE_V1.4.5102,2018.06.1418_44 Router/Netcore_NR289-GE_set_ntp_server_ip_command_injection.md at main · senxitoyshuyi-ui/HACKALL · GitHub