PT-2026-93187 · Unknown · Netcore Nr268

·

CVE-2026-76853

·

Published

2026-09-15

·

Updated

2026-09-15

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netcore NR268 version 1.7.121109
Description An issue exists in the restore archive prefix validation within the 'parame put file.cgi' endpoint. Attackers can exploit a flawed prefix check in the put parame file cgi.c file to bypass restricted restore archive handling.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76853

Affected Products

Netcore Nr268