Impact
The vulnerability stems from missing server‑side authorization checks on configuration endpoints of the Ebyte NE2‑D11 firmware. An attacker who can reach these endpoints may view or alter sensitive device settings without authentication. This lack of access control can lead to a full compromise of device functionality, potentially enabling remote manipulation or code execution.
Affected Systems
The affected product is the Ebyte NE2‑D11 firmware. Specific version information is not disclosed; the flaw exists in any model that exposes the described configuration endpoints.
Risk and Exploitability
The CVSS score of 8.7 places the flaw in the high severity range. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs network connectivity to the device’s management interface; no special privileges are required to exploit the authorization bypass. Once the unauthorized user modifies settings, the device’s normal operations can be disrupted or hijacked, thereby granting full control over the system.
OpenCVE Enrichment