CVE-2026-73125

9.8

Ebyte · NE2-D11 Firmware

The web management interface of Ebyte NE2-D11 firmware fails to enforce authentication, allowing unauthenticated remote attackers to modify device settings or disrupt availability.

Executive summary

The Ebyte NE2-D11 firmware contains a critical authentication bypass vulnerability that allows unauthenticated remote attackers to gain full control over device configurations.

Vulnerability

This is an authentication bypass vulnerability (CWE-306) occurring within the web management interface. The interface fails to consistently verify user credentials, enabling unauthenticated remote attackers to perform administrative actions.

Business impact

The vulnerability carries a CVSS score of 9.8, indicating a critical risk to organizational infrastructure. Successful exploitation allows unauthorized parties to modify critical device settings, potentially leading to a total loss of confidentiality, integrity, and availability for the affected network segment. This could result in significant operational downtime or the facilitation of further lateral movement within the environment.

Remediation

Immediate Action: Restrict network access to the web management interface of the Ebyte NE2-D11 device to authorized management subnets only until a firmware update is applied.

Proactive Monitoring: Review device access logs for unusual login patterns or administrative requests originating from unauthorized IP addresses.

Compensating Controls: Implement a Web Application Firewall or similar network security appliance to block unauthorized traffic directed at the web management interface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of this flaw, administrators must treat this as a high priority. Ensure that the vulnerable management interface is not accessible from untrusted networks and prepare to apply the vendor-supplied firmware update immediately upon its release to permanently remediate the authentication failure.

More Ebyte CVEs

Sources

Originally found and disclosed by Jithin Nambiar reported this vulnerability to CISA., per the CVE Program record.