CVE-2026-77977 affects Ebyte gateway products where the vendor configuration utility fails to require authentication for disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on the adjacent network can exploit this flaw to reboot the device or restore factory settings. This results in loss of configuration data and service availability. The vulnerability is classified as an authentication bypass issue tied to default credential configurations. It was reported via NVD and has an associated CISA ICS advisory (ICSA-26-237-06). The attack vector is adjacent network, limiting remote exploitation but still posing significant risk in industrial or OT environments. No active exploitation has been mentioned, but the impact on operational technology makes it high severity.