Impact
This vulnerability arises from a lack of separation between limited and administrative management functions in the Ebyte NA111-M firmware. An attacker with low‑privileged, authenticated access can reach security‑sensitive configuration options and alter settings that could compromise confidentiality, integrity, or availability of the device.
Affected Systems
The affected product is the Ebyte NA111-M firmware supplied by Ebyte.
Risk and Exploitability
The CVSS score of 8.7 signals a high severity risk. Exploitation requires legitimate credentials but does not require high privileges, indicating that a key‑based or authenticated attacker can manipulate configuration. EPSS data is unavailable, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA's KEV catalog. The likely attack path involves an attacker with basic credentials accessing the management interface and modifying configuration.
OpenCVE Enrichment