CVE-2026-75814
8.8Ebyte · NE2-D11 Firmware
The Ebyte NE2-D11 web management interface is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to trigger unauthorized configuration changes or service disruptions.
Executive summary
A critical CSRF vulnerability in Ebyte NE2-D11 firmware allows remote attackers to force administrative actions, potentially leading to total device compromise.
Vulnerability
This is a Cross-Site Request Forgery (CWE-352) vulnerability where the web management interface fails to verify the authenticity of requests. By luring an authenticated administrator to a malicious page, an unauthenticated attacker can execute unauthorized commands.
Business impact
The CVSS score of 8.8 reflects the high risk of unauthorized administrative control. Exploitation can result in the modification of critical device settings, session hijacking, and service disruption, which may lead to significant operational impairment for industrial or networked environments using this hardware.
Remediation
Immediate Action: As no patch is yet available, ensure that administrative sessions are closed immediately after use and avoid browsing untrusted websites while logged into the device management interface.
Proactive Monitoring: Monitor device logs for unauthorized configuration changes and review network traffic for suspicious requests originating from the management interface.
Compensating Controls: Implement strict browser-based security policies and use a dedicated, isolated management network to prevent external entities from interacting with the web interface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing the Ebyte NE2-D11 should mitigate risk by strictly limiting administrative access to trusted internal segments. Administrators must remain vigilant regarding their browsing habits during active sessions, as the integrity of the device relies on preventing the execution of forged requests by the authenticated user.
More Ebyte CVEs
Sources
Originally found and disclosed by Jithin Nambiar reported this vulnerability to CISA., per the CVE Program record.