CVE-2026-76853
Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in put_parame_file_cgi.c to bypass restricted restore archive handling.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.22%
- CWE
- CWE-353
- Published
- 2026-09-15
- Last modified
- 2026-09-16
Affected products
- Netcore NR268
Weakness type
Related vulnerabilities
- CVE-2021-26608 — handysoft groupware arbitrary file download and execution vulnerability
- CVE-2020-7810 — HandySoft ActiveX File Download and Execution Vulnerability
- CVE-2020-10266 — RVD#1487: No integrity checks on UR+ platform artifacts when installed in the robot
- CVE-2020-7808 — RAONWIZ Inc K Upload, arguments modiffication via missing support for integrity check vulnerability
- CVE-2019-11480 — Ubuntu kernel snap build process could use unauthenticated sources
- CVE-2021-28545 — Acrobat Reader DC Missing Support for Integrity Check
- CVE-2019-12804 — Hunesion i-oneNet Missing Support for Integrity Check vulnerability
- CVE-2023-32475 — Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system c