Description
The affected Ebyte

product exports administrative credentials and other
sensitive configuration information without adequate protection. An
unauthenticated attacker on the adjacent network who can obtain an
exported configuration file could recover valid credentials and use them
to access the device or similarly configured systems.
Published: 2026-08-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Credential Disclosure and Device Compromise
Action: Patch Immediately
AI Analysis

Impact

The vulnerability, classified as CWE-312 (Cleartext Storage of Sensitive Information), allows an attacker to obtain a configuration export file in cleartext from the Ebyte NE2-D11 firmware. The exported file contains administrative credentials and other sensitive configuration data. An attacker on the same local network, without needing to authenticate to the device first, can recover valid credentials and use them to access the device or any similarly configured system. The CVSS score of 7.1 indicates a high severity potential for compromise.

Affected Systems

Affected vendor: Ebyte. Product: Ebyte NE2-D11 Firmware. No specific version information is provided, so all firmware revisions of this product are potentially impacted until a patch is applied.

Risk and Exploitability

With no EPSS score available, the exploitation likelihood is uncertain, but the vulnerability’s high CVSS score and the fact that the attacker requires only local network proximity make the risk significant. The attacker can obtain credentials from a simple file download. The vulnerability is not listed in the CISA KEV catalog at this time, but the lack of a publicly available patch and the vendor’s uncoordinated response increase the urgency of remediation.

Generated by OpenCVE AI on August 31, 2026 at 16:37 UTC.

Remediation

Vendor Workaround

Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.


OpenCVE Recommended Actions

  • Apply the vendor‑released patch for the NE2‑D11 firmware as soon as it becomes available
  • Disable the configuration export feature or restrict it to authenticated users and store exported files in a secure location inaccessible to unauthenticated network traffic
  • Contact Ebyte for an updated remediation plan and verify whether the device can be reconfigured to prevent cleartext export of credentials

Generated by OpenCVE AI on August 31, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Ebyte
Ebyte ebyte Ne2-d11 Firmware
Vendors & Products Ebyte
Ebyte ebyte Ne2-d11 Firmware

Mon, 31 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use them to access the device or similarly configured systems.
Title Ebyte NA111-M Cleartext Storage of Sensitive Information
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ebyte Ebyte Ne2-d11 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-01T16:28:55.881Z

Reserved: 2026-08-21T19:56:57.903Z

Link: CVE-2026-77975

cve-icon Vulnrichment

Updated: 2026-09-01T16:21:38.913Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T16:19:13.190

Modified: 2026-09-01T17:17:35.243

Link: CVE-2026-77975

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information