Executive brief
The Netcore NR268 is a network router used to manage and secure internet connectivity in homes and small offices. A flaw in its firmware restore functionality allows authenticated attackers to bypass security checks and restore malicious configuration files, potentially compromising the entire network and all connected devices.
Technical details
The vulnerability is a security check bypass (CWE-353: Missing Support for Integrity Check) in the parame_put_file.cgi component, specifically in the prefix validation logic within put_parame_file_cgi.c. An authenticated attacker can craft a restore archive that bypasses the prefix check, allowing them to restore arbitrary configuration files to the device. The vulnerability requires authentication (PR:L) and network access; exploitation does not require user interaction. A successful attack enables an attacker to modify device configuration with high integrity impact (VI:H) and availability impact (VA:H), potentially leading to complete device compromise.
Affected products
- Netcore NR268 1.7.121109
Timeline
- 2026-09-15: disclosed
- 2026-09-04: advisory: Public reference published on GitHub