CVE-2026-76853High· 8.1▾ TwilightNetcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in put_parame_file_cgi.c to bypass restr…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in put_parame_file_cgi.c to bypass restricted restore archive handling.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-76852High· 8.8Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks
CVE-2026-94101Critical· 9.9A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246
CVE-2026-94100Critical· 9.9A weakness has been identified in Netcore NBR200V2 1.3.241127.071246
CVE-2026-94099Critical· 9.9A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246
CVE-2026-94098Critical· 9.1A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246
CVE-2026-94097Critical· 10.0A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246