GHSA-6645-rfg8-rhrmHighCVSS 8.8
Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in...
🔗 CVE IDs covered (1)
📋 Description
Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to bypass firmware signature validation and load unauthorized firmware images.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-76852
- https://github.com/draw-ctf/netcore-router-public-refs/blob/main/2026.08.19-netcore-nr268-firmware-forgery.md
- https://www.vulncheck.com/advisories/netcore-nr268-1.7.121109-forgeable-firmware-authenticity-check-in-mtd-write
- https://github.com/advisories/GHSA-6645-rfg8-rhrm