← Back to overview

CVE-2026-73819 affects an Ebyte product's vendor configuration utility, which allows access to administrative functions without proper identity verification under certain credential conditions. An unauthenticated attacker located on the adjacent network can exploit this flaw to modify critical device settings or change access credentials. This could result in legitimate administrators being locked out of device management. The vulnerability is classified as an authentication bypass or missing authentication for critical function issue. It is relevant to OT/ICS environments given the CISA ICS advisory association. The advisory is referenced by CISA under ICSA-26-237-06, indicating it has been reviewed as an industrial control system security concern. The attack vector requires adjacent network access, limiting but not eliminating the risk. The potential impact includes unauthorized configuration changes and disruption of legitimate administrative control.

Affected products

  • Ebyte vendor configuration utility

Related CVE's

  • CVE-2026-73819

Categories

  • Critical Infrastructure
  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure