This document proposes a new en-route filtering scheme called PCREF that can effectively filter false data injected by compromised sensor nodes in cyber-physical networked systems. PCREF uses polynomials instead of message authentication codes to endorse measurement reports, allowing it to be resilient to a large number of compromised nodes without relying on static routes or node localization. Analysis and experiments show that PCREF has better filtering capacity and resilience against a large number of compromised nodes compared to existing schemes.