← Terug naar overzicht

CVE-2026-76940 affects Ebyte devices that lack rate limiting and account lockout mechanisms for authentication attempts. This vulnerability enables attackers to perform automated brute-force or credential stuffing attacks against deployments using password-based authentication. The absence of these protective controls means there is no defense against repeated login attempts. The vulnerability is particularly concerning in operational technology (OT) and industrial control system (ICS) environments where Ebyte devices are commonly deployed. CISA has published an ICS advisory (ICSA-26-237-06) regarding this issue. Exploitation requires network access to the authentication interface of the affected device. The vulnerability is classified as an improper restriction of excessive authentication attempts. Organizations relying on password-based authentication for these devices are at elevated risk.

Affected products

  • Ebyte device

Related CVE's

  • CVE-2026-76940

Categories

  • Critical Infrastructure
  • Identity & Access
  • Mobile & IoT