← Terug naar overzicht

CVE-2026-77966 affects an Ebyte product that fails to properly separate limited user and administrative management functions. A low-privileged authenticated attacker can access security-sensitive configuration functions without proper authorization. The vulnerability allows modification of device settings that impact confidentiality, integrity, or availability. This is classified as an improper access control / privilege escalation issue in an OT/IoT device. The vulnerability was reported via NVD and has an associated CISA ICS advisory (ICSA-26-237-06). The issue poses a significant risk in operational technology environments where device integrity is critical. No exploit code is publicly referenced, but the low privilege requirement lowers the bar for exploitation.

Affected products

  • Ebyte

Related CVE's

  • CVE-2026-77966

Categories

  • Critical Infrastructure
  • Identity & Access
  • Mobile & IoT