Impact
The vulnerability, classified as CWE-312 (Cleartext Storage of Sensitive Information), allows an attacker to obtain a configuration export file in cleartext from the Ebyte NE2-D11 firmware. The exported file contains administrative credentials and other sensitive configuration data. An attacker on the same local network, without needing to authenticate to the device first, can recover valid credentials and use them to access the device or any similarly configured system. The CVSS score of 7.1 indicates a high severity potential for compromise.
Affected Systems
Affected vendor: Ebyte. Product: Ebyte NE2-D11 Firmware. No specific version information is provided, so all firmware revisions of this product are potentially impacted until a patch is applied.
Risk and Exploitability
With no EPSS score available, the exploitation likelihood is uncertain, but the vulnerability’s high CVSS score and the fact that the attacker requires only local network proximity make the risk significant. The attacker can obtain credentials from a simple file download. The vulnerability is not listed in the CISA KEV catalog at this time, but the lack of a publicly available patch and the vendor’s uncoordinated response increase the urgency of remediation.
OpenCVE Enrichment