Impact
The Ebyte NE2-D11 device allows repeated authentication attempts without any rate limiting or account lockout, making it vulnerable to brute‑force attacks. Attackers could repeatedly guess passwords at the authentication interface, ultimately gaining unauthorized access. This flaw, identified as CWE‑307, does not require privilege escalation or any special configuration from the attacker.
Affected Systems
All Ebyte NE2‑D11 firmware installations are affected, regardless of build version, because the vulnerability is tied to the core authentication logic rather than specific firmware revisions. Deployments that continue to rely on default or simple passwords are particularly at risk.
Risk and Exploitability
The vulnerability scored a CVSS score of 8.7, reflecting a high severity. Because EPSS is not available and the vulnerability is not listed in CISA KEV, we currently have no data on exploitation frequency but the lack of mitigation means an attacker could feasibly exploit it. The likely attack vector is automated, remote authentication requests that iterate over an attacker‑controlled list of credentials.
OpenCVE Enrichment