CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73125

criticalcovered by 1 sourcefirst seen 2026-08-25
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation. The following versions of Ebyte NE2-D11 are affected: NE2-D11 Firmware FW-9167-0-11 CVSS Vendor Equipment Vulnerabilities v3 9.8 Ebyte Ebyte NE2-D11 Missing Authentication for Critical Function, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials, Use of Client-Side Authentication, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Improper Restriction of Rendered UI Layers or Frames, Missing Authorization Background Critical Infrastructure Sectors: Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-73125 Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/

CSIRTS triage

What
Ebyte NE2-D11 firmware contains multiple critical authentication and authorization flaws including missing authentication, cleartext credential storage, and CSRF vulnerabilities.
Who is affected
All Ebyte NE2-D11 devices running firmware FW-9167-0-11 deployed in critical manufacturing and energy sectors.
Urgency
Critical; the combined vulnerabilities allow unauthorized administrative access, session hijacking, and configuration modification.
Action
Update NE2-D11 firmware to the patched version when released by Ebyte.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-73125

Get an email if CVE-2026-73125 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-73125

CVE.org record

Embed the live status

CVE-2026-73125 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73125 status](https://www.csirts.com/badge/CVE-2026-73125)](https://www.csirts.com/cve/CVE-2026-73125)