Executive brief
The Netcore NR268 is a network router used in residential and small business deployments. A flaw in its firmware update mechanism allows attackers to bypass signature validation and install malicious firmware images. This could lead to complete compromise of the router, enabling attackers to intercept network traffic, steal credentials, deploy ransomware, or use the device as a foothold for attacking connected networks.
Technical details
The vulnerability is an improper integrity verification flaw (CWE-354) in the mtd_write component of the Netcore NR268 firmware version 1.7.121109. Attackers can exploit the put_file.cgi endpoint and check_image_uuid.c functions to forge firmware authenticity checks and bypass signature validation. The vulnerability requires network access and authentication (login credentials) to exploit, but allows an authenticated attacker to load unauthorized firmware images onto the device. This results in complete device compromise. No patch information is currently available in the advisory.
Affected products
- Netcore NR268 1.7.121109
Timeline
- 2026-09-04: disclosed
- 2026-09-15: advisory