Impact
The vulnerability allows an unauthenticated attacker to invoke vendor configuration functions that can reboot or factory‑reset the device. Because no login is required when default credentials remain set, an attacker can disrupt service and erase user configuration, leading to denial of service and potential revenue loss.
Affected Systems
Ebyte NE2‑D11 gateway firmware with default credentials enabled. The threat applies to any unit running the supplied vendor configuration utility without enforcing authentication.
Risk and Exploitability
The CVSS score of 7.2 indicates a high level of risk, but the EPSS score is not available, making it uncertain how frequently the vulnerability may be targeted. The vulnerability is not listed in the CISA KEV catalog, but because it can be exploited by anyone on the same local network without authentication, the potential for abuse is significant. The likely attack vector is an unauthenticated attacker on the adjacent network, as no credentials are required to access the vendor config utility. Attackers need only network proximity, so the threat remains present until a patch is released and applied.
OpenCVE Enrichment