Impact
The Ebyte NE2-D11 firmware fails to verify the origin or authenticity of requests sent to its web management interface. An unauthenticated remote attacker can forge a request through a hyperlink or script that causes an authenticated administrator to unknowingly submit a configuration change. Because the request is treated as legitimate, the attacker can alter settings or disrupt device availability. This vulnerability represents a classic cross‑site request forgery flaw and is identified as CWE‑352.
Affected Systems
The vulnerability affects Ebyte NE2‑D11 firmware devices. No specific version numbers are available in the advisory, so all current installations of the NE2‑D11 firmware are potentially exposed.
Risk and Exploitability
The CVSS calculation yields a score of 8.6, indicating high severity. No EPSS score is publicly available, and the issue is not listed in the CISA KEV catalog. The likely attack vector involves a web‑based CSRF scenario, whereby the attacker coerces an authenticated administrator into visiting a crafted URL. Because the flaw allows configuration changes or service disruption without requiring local access or valid credentials, the risk to operational continuity is significant.
OpenCVE Enrichment