Impact
The vulnerability allows an attacker to replay or alter client‑managed authentication tokens because the Ebyte device does not perform adequate server‑side validation. An attacker can leverage this weakness to obtain elevated privileges and access administrative functions normally protected. The weakness is a classic example of insufficient access control, classified as CWE‑603, and can compromise the confidentiality and integrity of the device’s configuration and the services it exposes.
Affected Systems
The affected product is the Ebyte NE2‑D11 firmware. No additional version details are provided, so the risk applies to all revisions of the firmware currently in use.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability with significant impact. EPSS data is not available, but the lack of vendor‑issued patch and lack of KEV listing suggests the threat is not yet actively exploited at scale. The likely attack vector is remote, through the device’s management interface that accepts client‑issued tokens. Attack conditions require network reachability to the device and the ability to observe or intercept authentication traffic. Once the attacker obtains a valid token, they can perform administrative actions without further authentication.
OpenCVE Enrichment