Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in put_parame_file_cgi.c to bypass restricted restore archive handling.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in put_parame_file_cgi.c to bypass restricted restore archive handling. | |
| Title | Netcore NR268 1.7.121109 Security Check Bypass in parame_put_file.cgi | |
| Weaknesses | CWE-353 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T21:57:49.437Z
Reserved: 2026-08-19T21:47:08.935Z
Link: CVE-2026-76853
No data.
Status : Received
Published: 2026-09-15T22:16:59.070
Modified: 2026-09-15T22:16:59.070
Link: CVE-2026-76853
No data.
OpenCVE Enrichment
No data.
Weaknesses