← Terug naar overzicht

CVE-2026-77966 affects an Ebyte product that fails to properly separate limited user and administrative management functions. A low-privileged authenticated attacker can access security-sensitive configuration functions without proper authorization. This flaw allows unauthorized modification of device settings, potentially impacting the confidentiality, integrity, and availability of the device. The vulnerability is classified as an improper access control or broken access control issue. It is relevant to OT/ICS environments, as indicated by the CISA ICS advisory reference. CISA has published an advisory (ICSA-26-237-06) detailing the issue. The vulnerability poses a significant risk as it can be exploited by any authenticated low-privileged user on the device.

Affected products

  • Ebyte (unspecified product)

Related CVE's

  • CVE-2026-77966

Categories

  • Critical Infrastructure
  • Identity & Access
  • Mobile & IoT