Security & Threat Intelligence · 25.08.2026, 19:47 UTC
Ebyte NE2-D11
| Schweregrad | info |
|---|---|
| CVE | ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 25.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-69658, CVE-2026-71187, CVE-2026-73125, CVE-2026-73809, CVE-2026-73839. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation. The following versions of Ebyte NE2-D11 are affected:
NE2-D11 Firmware FW-9167-0-11
CVSS Vendor Equipment Vulnerabilities
v3 9.8 Ebyte Ebyte NE2-D11 Missing Authentication for Critical Function, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials, Use of Client-Side Authentication, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Improper Restriction of Rendered UI Layers or Frames, Missing Authorization
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: China
Vulnerabilities
Expand All +
CVE-2026-73125
Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. View CVE Details
Affected Products Ebyte NE2-D11
Vendor:Ebyte Product Version:Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status:known_affected
Remediations MitigationEbyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to …