CVE-2026-76133

9.8

Ebyte · Ebyte NA111-M Firmware

The Ebyte NA111-M firmware utilizes a deprecated hashing algorithm for authentication, which may allow an unauthenticated attacker to bypass security controls and gain unauthorized access.

Executive summary

A critical vulnerability exists in the Ebyte NA111-M firmware that exposes the device to unauthorized access due to the implementation of a deprecated hashing algorithm.

Vulnerability

The firmware employs a weak, deprecated hashing algorithm within its authentication mechanism. This flaw allows an unauthenticated attacker to manipulate the authentication exchange, effectively compromising the integrity of the login process and facilitating unauthorized access to the device.

Business impact

The use of weak cryptography for authentication poses a severe risk to operational security, as it enables unauthorized actors to gain full control over the affected device. Given the CVSS score of 9.8, this vulnerability is classified as critical, as it likely leads to complete system compromise, potential data theft, and the ability to pivot into deeper network segments.

Remediation

Immediate Action: Update the Ebyte NA111-M firmware to the latest available version provided by the manufacturer to replace the deprecated hashing algorithm.

Proactive Monitoring: Review device access logs for unusual patterns or failed authentication attempts that may indicate attempts to exploit the weak hashing implementation.

Compensating Controls: Isolate the affected device within a restricted management VLAN and use network-level access control lists to limit exposure to trusted management stations only.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

This vulnerability represents a critical security failure in the authentication chain of the Ebyte NA111-M firmware. Security teams must prioritize patching this device immediately, as the lack of authentication requirements makes the device an easy target for remote attackers. If an immediate firmware update is not feasible, the device should be removed from internet-facing environments until the vulnerability is fully remediated.

More Ebyte CVEs

Sources

Originally found and disclosed by Jithin Nambiar reported this vulnerability to CISA., per the CVE Program record.