PT-2026-93186 · Netcore · Nr268
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Netcore NR268 version 1.7.121109
Description
An improper integrity verification flaw exists in
mtd write, which allows for forged firmware authenticity checks. Attackers can exploit the 'put file.cgi' endpoint and the check image uuid.c file to bypass firmware signature validation and load unauthorized firmware images.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nr268