CVE-2026-77966

8.8

Ebyte · NA111-M Firmware

The Ebyte NA111-M firmware fails to properly separate user and administrative management functions, allowing low-privileged authenticated users to access and modify sensitive configuration settings.

Executive summary

A failure in privilege management within Ebyte NA111-M firmware allows authenticated attackers to perform unauthorized administrative actions, posing a high risk to device integrity.

Vulnerability

This is a missing authorization vulnerability (CWE-862) where the device does not enforce separation between limited and administrative management functions. A low-privileged authenticated attacker can bypass intended access controls to modify critical device configurations.

Business impact

The ability for a low-privileged user to alter administrative settings presents a significant security risk, potentially leading to unauthorized control, loss of device availability, or data compromise. With a CVSS score of 8.8, this vulnerability is classified as high severity, as it directly undermines the administrative security model of the affected hardware.

Remediation

Immediate Action: Since a specific patch version is currently unknown, users should restrict administrative network access to the device and monitor vendor communications for the release of a firmware update.

Proactive Monitoring: Security teams should review device access logs for unauthorized configuration changes or attempts by low-privileged accounts to access administrative endpoints.

Compensating Controls: Implement network-level segmentation to isolate the management interface of the Ebyte device, ensuring only authorized administrative workstations can reach the configuration portal.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score and the nature of the privilege escalation, this vulnerability requires urgent attention. Administrators should prioritize isolating affected devices from untrusted networks while awaiting official firmware remediation from Ebyte to resolve the authorization gap.

More Ebyte CVEs

Sources

Originally found and disclosed by Jithin Nambiar reported this vulnerability to CISA., per the CVE Program record.