CVE-2026-76853

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
8.1
HIGH

Description

Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in put_parame_file_cgi.c to bypass restricted restore archive handling.

Published
September 15, 2026 10:16 PM
Last Modified
September 15, 2026 10:16 PM
Source
[email protected]

Weaknesses (CWE)

CWE-353

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.