Description
The affected Ebyte

product does not provide separation between limited and administrative
management functions. A low privileged authenticated attacker could
access security sensitive configuration functions and modify settings
that affect the confidentiality, integrity, or availability of the
device.
Published: 2026-08-31
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from a lack of separation between limited and administrative management functions in the Ebyte NA111-M firmware. An attacker with low‑privileged, authenticated access can reach security‑sensitive configuration options and alter settings that could compromise confidentiality, integrity, or availability of the device.

Affected Systems

The affected product is the Ebyte NA111-M firmware supplied by Ebyte.

Risk and Exploitability

The CVSS score of 8.7 signals a high severity risk. Exploitation requires legitimate credentials but does not require high privileges, indicating that a key‑based or authenticated attacker can manipulate configuration. EPSS data is unavailable, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA's KEV catalog. The likely attack path involves an attacker with basic credentials accessing the management interface and modifying configuration.

Generated by OpenCVE AI on August 31, 2026 at 16:20 UTC.

Remediation

Vendor Workaround

Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.


OpenCVE Recommended Actions

  • Check for and apply any vendor patch or fix as soon as available.
  • Restrict access to the device’s management interfaces to trusted IP ranges and enable firewall rules to block unknown traffic.
  • Disable or lock any unused or unnecessary management functions to reduce attack surface.
  • If a patch is not yet released, isolate the device from untrusted networks and monitor for unauthorized changes.

Generated by OpenCVE AI on August 31, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Ebyte NE2-D11 Missing Authorization Ebyte NA111-M Missing Authorization

Mon, 31 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description The affected Ebyte product does not provide separation between limited and administrative management functions. A low privileged authenticated attacker could access security sensitive configuration functions and modify settings that affect the confidentiality, integrity, or availability of the device.
Title Ebyte NE2-D11 Missing Authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-31T15:46:49.952Z

Reserved: 2026-08-21T19:56:57.914Z

Link: CVE-2026-77966

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T16:19:13.053

Modified: 2026-08-31T16:19:13.053

Link: CVE-2026-77966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:30:05Z

Weaknesses