← Terug naar overzicht

CVE-2026-73819 describes an authentication bypass vulnerability in the Ebyte product's vendor configuration utility. The flaw allows access to administrative functions without proper identity verification under certain credential conditions. An unauthenticated attacker on the adjacent network can exploit this to modify critical device settings or change access credentials. This could result in legitimate administrators being locked out of device management. The vulnerability is classified as an ICS/OT security issue and is referenced in a CISA ICS advisory (ICSA-26-237-06). The attack vector requires adjacency to the network, limiting remote exploitation but still posing significant risk in industrial environments. No authentication is required for exploitation, lowering the barrier for attackers. The impact includes potential disruption of critical infrastructure management and unauthorized configuration changes.

Affected products

  • Ebyte vendor configuration utility

Related CVE's

  • CVE-2026-73819

Categories

  • Critical Infrastructure
  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure