An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality.
History

Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Ebyte NE2-D11 Use of GET Request Method With Sensitive Query Strings Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings

Fri, 28 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Ebyte
Ebyte ebyte Ne2-d11 Firmware
Vendors & Products Ebyte
Ebyte ebyte Ne2-d11 Firmware

Fri, 28 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality.
Title Ebyte NE2-D11 Use of GET Request Method With Sensitive Query Strings
Weaknesses CWE-598
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2026-08-27T21:22:53.600Z

Updated: 2026-08-31T15:50:06.756Z

Reserved: 2026-08-20T15:03:17.026Z

Link: CVE-2026-76179

cve-icon Vulnrichment

Updated: 2026-08-28T14:05:31.246Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T00:18:14.430

Modified: 2026-08-31T19:18:40.503

Link: CVE-2026-76179

cve-icon Redhat

No data.