Impact
Netcore NR268 firmware 1.7.121109 has an improper integrity verification flaw in the mtd_write function that allows attackers to forge firmware authenticity checks. This flaw enables the loading of unauthorized firmware images, which can result in remote code execution or complete device compromise. The weakness is categorized as CWE-354, improper validation of input data used by internal processes.
Affected Systems
The affected product is the Netcore NR268 router running firmware version 1.7.121109. No other products or versions were listed as impacted in the advisory.
Risk and Exploitability
The CVSS v3 score of 8.7 indicates a high severity. The EPSS score is less than 1% suggesting a low but non-zero probability of exploitation; it is not currently listed in the CISA KEV catalog. The vulnerability is likely exploitable via the web interface through the put_file.cgi and check_image_uuid.c paths, enabling an attacker to upload a forged firmware image and bypass signature validation. Because firmware updates are typically performed over an exposed network interface, the attack vector is inferred to be remote.
OpenCVE Enrichment