CVE-2026-76852: Netcore NR268
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to bypass firmware signature validation and load unauthorized firmware images.
Affected products
- Netcore NR268: version 1.7.121109 only
Published 2026-09-15. Last modified 2026-09-17.