Description
The Ebyte device relies on client side authentication logic that can be
reproduced by unauthenticated users. An attacker may generate valid
authentication requests and bypass authentication to obtain
administrative access to the device.
Published: 2026-08-27
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ebyte NE2‑D11 firmware uses authentication logic that is entirely executed on the client side, and this logic can be reproduced without any prior credentials. An attacker can craft valid authentication requests that the device accepts, thereby bypassing the intended security checks and gaining full administrative access. Once the administrative interface is compromised, the attacker can modify device configurations, install malicious code, or utilize the device for further network attacks. Based on the description, it is inferred that this can lead to remote code execution on the embedded platform.

Affected Systems

The vulnerability affects all Ebyte NE2‑D11 device firmware releases. No specific firmware version ranges are listed in the CNA data, so any deployed instance of the NE2‑D11 should be considered potentially vulnerable. The impact applies regardless of the installation method or operating environment.

Risk and Exploitability

The CVSS base score of 9.3 classifies this flaw as critical, and the absence of an EPSS value means modern exploitation likelihood is unknown but the vulnerability remains serious. The asset is not listed in CISA’s KEV catalog, however the lack of vendor coordination and a pending patch increases the risk that attackers may exploit the flaw in the meantime. The likely attack vector is an unauthenticated network connection to the device, where an attacker can send crafted authentication packets. With this access the attacker can take administrative control, leading to high‑severity compromise of confidentiality, integrity, and availability. Based on the description, it is inferred that remote code execution is possible.

Generated by OpenCVE AI on August 28, 2026 at 07:41 UTC.

Remediation

Vendor Workaround

Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.


OpenCVE Recommended Actions

  • Contact Ebyte to expedite the pending firmware patch and confirm deployment status
  • Limit device access to a trusted network segment and block inbound connections from untrusted networks
  • Disable remote administration or client‑side authentication mechanisms if the device allows it until a secure firmware update is issued

Generated by OpenCVE AI on August 28, 2026 at 07:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Ebyte
Ebyte ebyte Ne2-d11 Firmware
Vendors & Products Ebyte
Ebyte ebyte Ne2-d11 Firmware

Fri, 28 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.
Title Ebyte NE2-D11 Use of Client-Side Authentication
Weaknesses CWE-603
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ebyte Ebyte Ne2-d11 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-28T14:13:52.670Z

Reserved: 2026-08-20T15:03:17.023Z

Link: CVE-2026-71187

cve-icon Vulnrichment

Updated: 2026-08-28T14:05:38.417Z

cve-icon NVD

Status : Received

Published: 2026-08-28T00:18:09.150

Modified: 2026-08-28T16:18:23.910

Link: CVE-2026-71187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:13:39Z

Weaknesses
  • CWE-603

    Use of Client-Side Authentication