CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Ebyte NA111-M

criticalCVE-2026-73125CVE-2026-76179CVE-2026-75814CVE-2026-76940CVE-2026-77966CVE-2026-73809
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device. The following versions of Ebyte NA111-M are affected: NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977) CVSS Vendor Equipment Vulnerabilities v3 9.8 Ebyte Ebyte NA111-M Missing Authentication for Critical Function, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Missing Authorization, Cleartext Transmission of Sensitive Information, Use of Client-Side Authentication, Improper Restriction of Rendered UI Layers or Frames, Use of a Broken or Risky Cryptographic Algorithm, Weak Authentication, Cleartext Storage of Sensitive Information Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-73125 Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. View CVE Details Affected Products Ebyte NA111-M Vendor: Ebyte Product Version: Ebyte NA111-M Firmware: 9013-2-17 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Scor

CSIRTS triage

vendor: Ebyteproduct: NA111-MAuthentication bypassCross-site request forgeryInformation disclosureMisconfigurationaffected: Firmware 9013-2-17
What
Multiple authentication and authorization flaws including missing authentication for critical functions, CSRF, weak cryptographic algorithms, and cleartext transmission of sensitive data.
Who is affected
Ebyte NA111-M devices running firmware version 9013-2-17.
Urgency
Critical severity with CVSS 9.8 indicates full device compromise is possible; immediate action is required.
Action
Update firmware to a patched version addressing the documented authentication and encryption weaknesses.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch NA111-M

Get an email when a new NA111-M advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-08-27
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-73125coverage & exploitation statusNVD · CVE.org
CVE-2026-76179coverage & exploitation statusNVD · CVE.org
CVE-2026-75814coverage & exploitation statusNVD · CVE.org
CVE-2026-76940coverage & exploitation statusNVD · CVE.org
CVE-2026-77966coverage & exploitation statusNVD · CVE.org
CVE-2026-73809coverage & exploitation statusNVD · CVE.org
CVE-2026-71187coverage & exploitation statusNVD · CVE.org
CVE-2026-75548coverage & exploitation statusNVD · CVE.org
CVE-2026-69658coverage & exploitation statusNVD · CVE.org
CVE-2026-76133coverage & exploitation statusNVD · CVE.org
CVE-2026-73819coverage & exploitation statusNVD · CVE.org
CVE-2026-77975coverage & exploitation statusNVD · CVE.org
CVE-2026-77977coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories