CVE-2026-76853: Netcore NR268 1.7.121109 Security Check Bypass in parame_put_file.cgi
Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parameputfile.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in putparamefilecgi.c to bypass restricted restore archive handling.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.7.121109Patch Netcore NR268
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability has a low-privileges requirement (PR:L). An attacker must already have access sufficient to reach and use the affected restore functionality; no user interaction is required.
What security impact can exploitation have?
Successful exploitation can compromise integrity and availability, while no confidentiality impact is indicated. The issue bypasses restricted restore archive handling through flawed archive prefix validation.
Which firmware version is identified as affected?
The provided information identifies Netcore NR268 firmware version 1.7.121109 as containing the vulnerability. No affected version range, fixed version, or default-configuration status is provided.