Ebyte NE2-D11
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation. The following versions of Ebyte NE2-D11 are affected: NE2-D11 Firmware FW-9167-0-11 CVSS Vendor Equipment Vulnerabilities v3 9.8 Ebyte Ebyte NE2-D11 Missing Authentication for Critical Function, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials, Use of Client-Side Authentication, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Improper Restriction of Rendered UI Layers or Frames, Missing Authorization Background Critical Infrastructure Sectors: Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-73125 Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/
CSIRTS triage
- What
- Ebyte NE2-D11 firmware contains multiple critical authentication and authorization flaws including missing authentication, cleartext credential storage, and CSRF vulnerabilities.
- Who is affected
- All Ebyte NE2-D11 devices running firmware FW-9167-0-11 deployed in critical manufacturing and energy sectors.
- Urgency
- Critical; the combined vulnerabilities allow unauthorized administrative access, session hijacking, and configuration modification.
- Action
- Update NE2-D11 firmware to the patched version when released by Ebyte.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Ebyte NE2-D11
Get an email when a new Ebyte NE2-D11 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-73125 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73809 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73839 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71187 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76179 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75814 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76940 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75548 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75813 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76945 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-69658 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-76945: The affected Ebyte device relies on client-managed authentication tokens without sufficient se…nvd
- highCVE-2026-76940: The affected Ebyte device does not restrict repeated authentication attempts through rate limi…nvd
- criticalCVE-2026-76179: An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway …nvd
- highCVE-2026-75814: The Ebyte device does not adequately verify the origin or authenticity of requests submitted t…nvd
- highCVE-2026-75813: Certain configuration endpoints may lack proper server-side authorization checks, allowing una…nvd
- mediumCVE-2026-75548: The affected Ebyte device web management interface does not restrict the interface from being …nvd
- mediumCVE-2026-73839: Administrative credentials may be exposed in plaintext within the Ebyte device's management in…nvd
- highCVE-2026-73809: A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gatewa…nvd
- criticalCVE-2026-73125: Ebyte device web management interface does not consistently enforce authentication before gran…nvd
- criticalCVE-2026-71187: The Ebyte device relies on client side authentication logic that can be reproduced by unauthen…nvd
- criticalCVE-2026-69658: MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive informat…nvd
- criticalEbyte NA111-Mcisa
More from CISA Cybersecurity Advisories
- criticalCareCam Pro IP Cameras2026-09-08
- unknownChina-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. …2026-09-08
- highCISA Adds Four Known Exploited Vulnerabilities to Catalog2026-09-08
- highCISA Adds One Known Exploited Vulnerability to Catalog2026-09-04
- criticalPyramid Solutions NetStaX EtherNet/IP Stack2026-09-03