← Terug naar overzicht

CISA published an ICS advisory for the Ebyte NE2-D11 gateway device running firmware FW-9167-0-11, disclosing 11 vulnerabilities with a maximum CVSS v3 score of 9.8 (Critical). The vulnerabilities span missing authentication, cleartext transmission, insufficiently protected credentials, client-side authentication bypass, session hijacking via GET parameters, CSRF, brute-force susceptibility, clickjacking, missing authorization, and cleartext MQTT traffic. Successful exploitation could allow unauthenticated remote attackers to gain administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation. The affected product is deployed worldwide in Critical Manufacturing and Energy sectors. Ebyte acknowledged the vulnerabilities and indicated a patch was under development but has not responded to subsequent coordination requests, leaving no vendor patch available. CISA recommends network isolation, firewall segmentation, and VPN usage as mitigations. The vulnerabilities were reported by researcher Jithin Nambiar.

Affected products

  • Ebyte NE2-D11 Firmware FW-9167-0-11

Related CVE's

  • CVE-2026-69658
  • CVE-2026-71187
  • CVE-2026-73125
  • CVE-2026-73809
  • CVE-2026-73839
  • CVE-2026-75548
  • CVE-2026-75813
  • CVE-2026-75814
  • CVE-2026-76179
  • CVE-2026-76940
  • CVE-2026-76945

Categories

  • Critical Infrastructure
  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure