Ebyte NA111-M
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device. The following versions of Ebyte NA111-M are affected: NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977) CVSS Vendor Equipment Vulnerabilities v3 9.8 Ebyte Ebyte NA111-M Missing Authentication for Critical Function, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Missing Authorization, Cleartext Transmission of Sensitive Information, Use of Client-Side Authentication, Improper Restriction of Rendered UI Layers or Frames, Use of a Broken or Risky Cryptographic Algorithm, Weak Authentication, Cleartext Storage of Sensitive Information Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-73125 Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. View CVE Details Affected Products Ebyte NA111-M Vendor: Ebyte Product Version: Ebyte NA111-M Firmware: 9013-2-17 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Scor
CSIRTS triage
- What
- Multiple authentication and authorization flaws including missing authentication for critical functions, CSRF, weak cryptographic algorithms, and cleartext transmission of sensitive data.
- Who is affected
- Ebyte NA111-M devices running firmware version 9013-2-17.
- Urgency
- Critical severity with CVSS 9.8 indicates full device compromise is possible; immediate action is required.
- Action
- Update firmware to a patched version addressing the documented authentication and encryption weaknesses.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch NA111-M
Get an email when a new NA111-M advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-73125 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76179 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75814 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76940 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77966 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73809 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71187 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75548 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-69658 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76133 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73819 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77975 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77977 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-77975: The affected Ebyte product exports administrative credentials and other sensitive configuratio…nvd
- highCVE-2026-77966: The affected Ebyte product does not provide separation between limited and administrative mana…nvd
- criticalCVE-2026-76133: The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related op…nvd
- criticalCVE-2026-73819: The affected Ebyte product's vendor configuration utility permits access to administrative fun…nvd
- highCVE-2026-77977: Ebyte gateway product's vendor configuration utility does not require authentication before al…nvd
- highCVE-2026-76940: The affected Ebyte device does not restrict repeated authentication attempts through rate limi…nvd
- criticalCVE-2026-76179: An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway …nvd
- highCVE-2026-75814: The Ebyte device does not adequately verify the origin or authenticity of requests submitted t…nvd
- mediumCVE-2026-75548: The affected Ebyte device web management interface does not restrict the interface from being …nvd
- highCVE-2026-73809: A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gatewa…nvd
- criticalCVE-2026-73125: Ebyte device web management interface does not consistently enforce authentication before gran…nvd
- criticalCVE-2026-71187: The Ebyte device relies on client side authentication logic that can be reproduced by unauthen…nvd
More from CISA Cybersecurity Advisories
- criticalCareCam Pro IP Cameras2026-09-08
- unknownChina-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. …2026-09-08
- highCISA Adds Four Known Exploited Vulnerabilities to Catalog2026-09-08
- highCISA Adds One Known Exploited Vulnerability to Catalog2026-09-04
- criticalPyramid Solutions NetStaX EtherNet/IP Stack2026-09-03