CVE-2026-76852
moderateFirmware Signature Verification Bypass in Netcore NR268 Router
Netcore NR268 router firmware version 1.7.121109 contains an improper integrity verification flaw (CWE-354) in the mtd_write component, involving the put_file.cgi endpoint and check_image_uuid.c logic. An attacker with low privileges, such as access to the device's web management interface, can upload a crafted firmware image whose authenticity checks can be forged, bypassing signature validation and installing unauthorized firmware. Successful exploitation yields full control of the router with high impact on confidentiality, integrity, and availability (CVSS 4.0: 8.7), enabling persistent backdoors and interception of routed traffic. Organizations running the NR268 on the affected firmware, particularly devices with remotely reachable administration, are at risk. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported to date.
What to do: Contact Netcore for a firmware release newer than 1.7.121109, as no fixed version is listed in the advisory. Until patched, disable WAN-side access to the router's web administration (including put_file.cgi) so management is reachable only from a trusted LAN or VPN segment. Audit device logs and firmware versions for unexpected image uploads or configuration changes, and consider replacing end-of-life units that cannot be upgraded.
| Netcore NR268 router firmware | 1.7.121109 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to bypass firmware signature validation and load unauthorized firmware images.
- Weakness
- CWE-354
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.