CVE-2026-76852

Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to bypass firmware signature validation and load unauthorized firmware images.

  • Published Sep 15, 2026
  • CVSS 8.7 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-76852 at the National Vulnerability Database