← Terug naar overzicht

CISA issued an ICS advisory (ICSA-26-239-05) for Ebyte NA111-M Firmware 9013-2-17, disclosing 13 vulnerabilities with a maximum CVSS v3 score of 9.8 (Critical). Successful exploitation could allow an attacker to fully compromise the device. Vulnerabilities include Missing Authentication for Critical Functions, CSRF, Use of Client-Side Authentication, Cleartext Transmission of Sensitive Information (HTTP and MQTT), Weak Authentication, Missing Authorization, Broken Cryptographic Algorithms, and Cleartext Storage of Sensitive Information. The device is deployed worldwide in the Information Technology critical infrastructure sector by China-based vendor Ebyte. Ebyte acknowledged the vulnerabilities and indicated a patch was under development but has not responded to subsequent coordination requests. No patch is currently available; CISA recommends network isolation, firewall segmentation, and VPN use as mitigations. The vulnerabilities were reported by Jithin Nambiar J.

Affected products

  • Ebyte NA111-M Firmware 9013-2-17

Related CVE's

  • CVE-2026-69658
  • CVE-2026-71187
  • CVE-2026-73125
  • CVE-2026-73809
  • CVE-2026-73819
  • CVE-2026-75548
  • CVE-2026-75814
  • CVE-2026-76133
  • CVE-2026-76179
  • CVE-2026-76940
  • CVE-2026-77966
  • CVE-2026-77975
  • CVE-2026-77977

Categories

  • Critical Infrastructure
  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure

Related links