Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to bypass firmware signature validation and load unauthorized firmware images.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to bypass firmware signature validation and load unauthorized firmware images. | |
| Title | Netcore NR268 1.7.121109 Forgeable Firmware Authenticity Check in mtd_write | |
| Weaknesses | CWE-354 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T21:57:48.762Z
Reserved: 2026-08-19T21:47:08.935Z
Link: CVE-2026-76852
No data.
Status : Deferred
Published: 2026-09-15T22:16:58.887
Modified: 2026-09-16T19:47:01.197
Link: CVE-2026-76852
No data.
OpenCVE Enrichment
Updated: 2026-09-16T20:45:05Z
Weaknesses