Impact
The vulnerability allows administrative credentials to be exposed in plaintext within the device's management interface, compromising the confidentiality of device access. This deficiency, identified as CWE-522, means an attacker who can observe the interface—either visually or through network traffic—can obtain the credentials. Based on the description, it is inferred that if an attacker obtains the credentials, they could potentially gain unauthorized administrative control over the device, potentially leading to further exploitation of the system.
Affected Systems
The affected product is the Ebyte NE2-D11 firmware. No additional version information is provided.
Risk and Exploitability
The CVSS score of 5.1 reflects a moderate risk. The EPSS score is not available, so the likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no known exploitation in the wild. The attack vector is most likely through the device’s management interface, accessible remotely or locally, allowing an adversary to observe or intercept credentials. Without an official patch, the risk remains until a firmware update is released.
OpenCVE Enrichment