Impact
The Ebyte NE2‑D11 firmware uses authentication logic that is entirely executed on the client side, and this logic can be reproduced without any prior credentials. An attacker can craft valid authentication requests that the device accepts, thereby bypassing the intended security checks and gaining full administrative access. Once the administrative interface is compromised, the attacker can modify device configurations, install malicious code, or utilize the device for further network attacks. Based on the description, it is inferred that this can lead to remote code execution on the embedded platform.
Affected Systems
The vulnerability affects all Ebyte NE2‑D11 device firmware releases. No specific firmware version ranges are listed in the CNA data, so any deployed instance of the NE2‑D11 should be considered potentially vulnerable. The impact applies regardless of the installation method or operating environment.
Risk and Exploitability
The CVSS base score of 9.3 classifies this flaw as critical, and the absence of an EPSS value means modern exploitation likelihood is unknown but the vulnerability remains serious. The asset is not listed in CISA’s KEV catalog, however the lack of vendor coordination and a pending patch increases the risk that attackers may exploit the flaw in the meantime. The likely attack vector is an unauthenticated network connection to the device, where an attacker can send crafted authentication packets. With this access the attacker can take administrative control, leading to high‑severity compromise of confidentiality, integrity, and availability. Based on the description, it is inferred that remote code execution is possible.
OpenCVE Enrichment