CVE-2026-73819
9.8Ebyte · Ebyte NA111-M Firmware
The Ebyte NA111-M firmware contains an authentication bypass vulnerability in its configuration utility, allowing unauthenticated attackers to modify critical settings or credentials.
Executive summary
An unauthenticated authentication bypass vulnerability in the Ebyte NA111-M firmware permits remote attackers to take full control of device settings and administrative access.
Vulnerability
The configuration utility fails to verify operator identity for administrative functions, allowing an unauthenticated attacker on the adjacent network to perform unauthorized changes.
Business impact
Successful exploitation poses a severe risk to operational integrity, as attackers can modify device configurations or lock out legitimate administrators. Given the critical CVSS score of 9.8, this vulnerability facilitates full administrative compromise, which may lead to prolonged system downtime or unauthorized control over industrial operations.
Remediation
Immediate Action: Update the Ebyte NA111-M firmware to the latest available version provided by the vendor to remediate the authentication bypass.
Proactive Monitoring: Review device access logs for unauthorized configuration changes and monitor adjacent network traffic for suspicious connection attempts to the configuration utility.
Compensating Controls: Restrict access to the device management interface by placing it on a segmented, isolated network and applying strict firewall rules to limit who can reach the configuration utility.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a critical risk to device availability and integrity. Organizations utilizing the Ebyte NA111-M firmware must prioritize the application of the vendor-supplied firmware update to eliminate the bypass vector immediately.
More Ebyte CVEs
Sources
Originally found and disclosed by Jithin Nambiar reported this vulnerability to CISA., per the CVE Program record.