CVE-2026-73125
9.8Ebyte · NE2-D11 Firmware
The web management interface of Ebyte NE2-D11 firmware fails to enforce authentication, allowing unauthenticated remote attackers to modify device settings or disrupt availability.
Executive summary
The Ebyte NE2-D11 firmware contains a critical authentication bypass vulnerability that allows unauthenticated remote attackers to gain full control over device configurations.
Vulnerability
This is an authentication bypass vulnerability (CWE-306) occurring within the web management interface. The interface fails to consistently verify user credentials, enabling unauthenticated remote attackers to perform administrative actions.
Business impact
The vulnerability carries a CVSS score of 9.8, indicating a critical risk to organizational infrastructure. Successful exploitation allows unauthorized parties to modify critical device settings, potentially leading to a total loss of confidentiality, integrity, and availability for the affected network segment. This could result in significant operational downtime or the facilitation of further lateral movement within the environment.
Remediation
Immediate Action: Restrict network access to the web management interface of the Ebyte NE2-D11 device to authorized management subnets only until a firmware update is applied.
Proactive Monitoring: Review device access logs for unusual login patterns or administrative requests originating from unauthorized IP addresses.
Compensating Controls: Implement a Web Application Firewall or similar network security appliance to block unauthorized traffic directed at the web management interface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of this flaw, administrators must treat this as a high priority. Ensure that the vulnerable management interface is not accessible from untrusted networks and prepare to apply the vendor-supplied firmware update immediately upon its release to permanently remediate the authentication failure.
More Ebyte CVEs
Sources
Originally found and disclosed by Jithin Nambiar reported this vulnerability to CISA., per the CVE Program record.