Impact
The vulnerability stems from missing authentication on the web management interface of the Ebyte NE2-D11 firmware, allowing anyone on the network to reach administrative functions. The attacker can read sensitive configuration, change device settings, or shut down services, which compromises confidentiality, integrity, and availability of the device.
Affected Systems
The affected product is the Ebyte NE2‑D11 firmware from Ebyte. No specific version numbers are provided in the available data.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity condition. EPSS information is unavailable, so the exact likelihood of exploitation is unknown, yet the lack of authentication makes the vulnerability highly exploitable through the web interface. The vulnerability is not yet listed in the CISA KEV catalog. An attacker would likely access the device remotely via the exposed web management interface to gain unrestricted administrative capabilities.
OpenCVE Enrichment