Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.
History

Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Ebyte NE2-D11 Missing Authentication for Critical Function Ebyte NA111-M Missing Authentication for Critical Function

Fri, 28 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Ebyte
Ebyte ebyte Ne2-d11 Firmware
Vendors & Products Ebyte
Ebyte ebyte Ne2-d11 Firmware

Fri, 28 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.
Title Ebyte NE2-D11 Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2026-08-27T21:13:10.725Z

Updated: 2026-08-31T15:51:28.700Z

Reserved: 2026-08-20T15:03:17.014Z

Link: CVE-2026-73125

cve-icon Vulnrichment

Updated: 2026-08-28T14:05:59.969Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T00:18:11.273

Modified: 2026-08-31T19:18:40.503

Link: CVE-2026-73125

cve-icon Redhat

No data.