Improper Integrity Verification in Netcore NR268 Firmware by Netcore
CVE-2026-76852

8.7HIGH

Key Information:

Vendor

Netcore

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-76852?

The Netcore NR268 firmware version 1.7.121109 suffers from a significant flaw where improper integrity verification in the mtd_write function compromises firmware security. This vulnerability enables attackers to exploit the put_file.cgi and check_image_uuid.c scripts, effectively bypassing the essential firmware signature validation process. As a result, unauthorized and potentially malicious firmware images can be loaded, posing serious risks to device integrity and network security.

Affected Version(s)

NR268 1.7.121109

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
.