CVE-2026-101077 PUBLISHED

Netcore NR289-GE boa_temp process_request missing authentication

Assigner: VulDB
Reserved: 27.09.2026 Published: 28.09.2026 Updated: 28.09.2026

A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
CVSS Score: 10

Product Status

Vendor Netcore
Product NR289-GE
Versions
  • Version 1.4.5102 is affected

Credits

  • yyycl (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Missing Authentication CWE
  • Improper Authentication CWE