Impact
The vulnerability in Ebyte NA111‑M Firmware arises from the use of a deprecated hashing algorithm within an authentication-related operation. In circumstances where an attacker can influence or predict the authentication exchange, the weakened hash construction diminishes the reliability of the authentication process and can be exploited to gain unauthorized access to the device or its functions.
Affected Systems
Ebyte NA111‑M Firmware is impacted. No specific firmware version numbers are provided, so all releases of this product should be considered at risk until a vendor patch is issued.
Risk and Exploitability
The vulnerability rates a CVSS score of 9.3, indicating high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that a public exploit has not yet been observed. The likely attack vector is through manipulation of the authentication exchange, which requires the attacker to have some degree of interaction with the device and the ability to send crafted authentication messages. Given the high CVSS score, the potential impact of successful exploitation is significant, especially in environments where the device authenticates critical processes or controls essential operations.
OpenCVE Enrichment