Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in put_parame_file_cgi.c to bypass restricted restore archive handling. | |
| Title | Netcore NR268 1.7.121109 Security Check Bypass in parame_put_file.cgi | |
| Weaknesses | CWE-353 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T19:08:16.783Z
Reserved: 2026-08-19T21:47:08.935Z
Link: CVE-2026-76853
Updated: 2026-09-16T19:08:12.511Z
Status : Deferred
Published: 2026-09-15T22:16:59.070
Modified: 2026-09-16T20:21:01.047
Link: CVE-2026-76853
No data.
OpenCVE Enrichment
Updated: 2026-09-16T20:45:05Z
-
CWE-353
Missing Support for Integrity Check