Impact
The vulnerability is a cleartext transmission of sensitive information in the Ebyte NE2‑D11 web management interface. Authentication and session data are sent without transport‑layer encryption, allowing an adversary who can observe network traffic to capture credentials and other confidential information. The primary impact is the loss of confidentiality and the possibility of unauthorized device management. The weakness is classified as CWE‑319.
Affected Systems
The affected product is the Ebyte NE2‑D11 firmware. Version details are not specified, so all current and future releases of the NE2‑D11 should be considered vulnerable until a vendor patch is deployed.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity issue. Exploitation requires only passive monitoring of network traffic to capture cleartext data; no active exploitation or administrative privileges are needed. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that while the technical risk is high, real‑world exploitation is at least moderate but unconfirmed. Because no patch has been released, mitigations must rely on network segmentation or access restrictions until an official fix is available.
OpenCVE Enrichment