Impact
The vulnerability exists in the Ebyte NA111‑M firmware’s vendor configuration utility and allows an unauthenticated user on the adjacent network to access administrative functions without identity verification. This flaw enables an attacker to modify critical device settings or replace administrator credentials, effectively bypassing authentication and potentially denying legitimate administrators access. The weakness corresponds to CWE‑1390, an authentication bypass.
Affected Systems
The CNA data lists only the Ebyte NA111‑M firmware as affected; no other vendor or product variations are identified.
Risk and Exploitability
The CVSS score of 9.3 indicates severe impact and high exploitability. EPSS data is unavailable, but the absence of a publicly released patch combined with the ability of an unauthenticated local network attacker to manipulate configuration settings keeps the risk high. The device is referenced in the ICA advisory but is not yet listed in the KEV catalog. Attackers are inferred to target the device from the local network, exploiting the configuration utility’s lack of authentication checks.
OpenCVE Enrichment