ZeroHour

CVE-2026-76852

moderate

Firmware Signature Verification Bypass in Netcore NR268 Router

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Netcore NR268 router firmware version 1.7.121109 contains an improper integrity verification flaw (CWE-354) in the mtd_write component, involving the put_file.cgi endpoint and check_image_uuid.c logic. An attacker with low privileges, such as access to the device's web management interface, can upload a crafted firmware image whose authenticity checks can be forged, bypassing signature validation and installing unauthorized firmware. Successful exploitation yields full control of the router with high impact on confidentiality, integrity, and availability (CVSS 4.0: 8.7), enabling persistent backdoors and interception of routed traffic. Organizations running the NR268 on the affected firmware, particularly devices with remotely reachable administration, are at risk. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported to date.

What to do: Contact Netcore for a firmware release newer than 1.7.121109, as no fixed version is listed in the advisory. Until patched, disable WAN-side access to the router's web administration (including put_file.cgi) so management is reachable only from a trusted LAN or VPN segment. Audit device logs and firmware versions for unexpected image uploads or configuration changes, and consider replacing end-of-life units that cannot be upgraded.

Affected
Netcore NR268 router firmware1.7.121109
Estimated exposure
moderateestimated low thousands to ~10k internet-exposed devices — Netcore/netis SOHO and small-business routers are routinely observed in internet-wide scans (Shodan/Censys) primarily in China and Southeast Asia, but exact counts of internet-exposed NR268 units are not available, so this is a rough…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to bypass firmware signature validation and load unauthorized firmware images.

Weakness
CWE-354
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.