← Terug naar overzicht

CVE-2026-75814 affects Ebyte devices, which fail to adequately verify the origin or authenticity of requests to their web management interface. This cross-site request forgery (CSRF) vulnerability allows an unauthenticated remote attacker to trick an authenticated administrator into visiting a crafted page. Successful exploitation can result in unauthorized configuration changes or disruption of device availability. The vulnerability requires social engineering of an authenticated administrator but does not require the attacker to be authenticated themselves. It has been reported via NVD and is associated with an ICS advisory published by CISA (icsa-26-237-06). Given its impact on device availability and configuration integrity, it poses a significant risk to operational technology environments. The CSAF advisory is available through CISA's GitHub repository.

Affected products

  • Ebyte device

Related CVE's

  • CVE-2026-75814

Categories

  • Critical Infrastructure
  • Mobile & IoT
  • Network Infrastructure