CVE-2026-73125 describes a critical authentication bypass vulnerability in the Ebyte device web management interface. The interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker can exploit this flaw to access sensitive configuration information, modify device settings, or disrupt device availability. The vulnerability is categorized as missing authentication for critical function. It affects OT/IoT network devices manufactured by Ebyte. CISA has published an ICS advisory (ICSA-26-237-06) addressing this issue. The flaw poses significant risk to industrial and operational technology environments where Ebyte devices are deployed. No authentication or special privileges are required to exploit this vulnerability remotely.