ZeroHour

CVE-2026-76853

Restore Archive Security Check Bypass in Netcore NR268 Router Firmware

CVSS 4.0
7.2 high
EPSS
Published
()
Modified
AI analysis

Netcore NR268 router firmware version 1.7.121109 contains a security check bypass in the parame_put_file.cgi endpoint, where flawed prefix validation of uploaded restore archives in put_parame_file_cgi.c fails to properly restrict which archives can be processed. A remote attacker with low privileges (i.e., an authenticated user of the device's web interface) can craft a restore archive that slips past the prefix check and have it handled by the restricted restore mechanism. Successful exploitation gives the attacker high control over device integrity and availability — for example, by restoring a malicious configuration or otherwise tampering with router state — though no direct confidentiality impact is indicated. The flaw affects Netcore NR268 units running firmware 1.7.121109, an enterprise-oriented router primarily deployed in China and Southeast Asian markets. There is no known public proof of concept and no evidence of exploitation in the wild; the issue is not on the CISA KEV list.

What to do: Check with Netcore for a firmware release newer than 1.7.121109 that fixes the parame_put_file.cgi prefix validation and upgrade affected NR268 units as soon as one is available. In the interim, do not expose the router's web management interface to the internet, restrict administrative and restore/upload privileges to trusted accounts only, and change any default credentials. Monitor device logs for unexpected archive restore or configuration-change events.

Affected
Netcore NR2681.7.121109
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in put_parame_file_cgi.c to bypass restricted restore archive handling.

Weakness
CWE-353
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.