Impact
In the Ebyte NE2-D11 firmware, MQTT credentials and control traffic are transmitted in cleartext, which allows an attacker to capture sensitive data, authenticate as the device, and potentially disrupt messaging functions. This weakness falls under CWE-319, exposing both confidentiality and integrity of the device communication.
Affected Systems
The vulnerability affects the Ebyte NE2-D11 firmware. No specific firmware version information is provided, and the vendor has not yet released a patch.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score is currently unavailable, so the exact exploitation probability is uncertain, but the lack of encryption makes this a low-cost vector for network‑level attackers who can sniff traffic. The vulnerability is not listed in the CISA KEV catalog, suggesting no known exploitation yet, yet the broad network exposure keeps the risk high.
OpenCVE Enrichment