Executive brief
The Ebyte NE2-D11 is an industrial IoT gateway device used to manage critical infrastructure communications. An attacker positioned on the network can intercept unencrypted MQTT credentials and control traffic, enabling unauthorized device impersonation, session hijacking, and disruption of messaging operations across connected systems.
Technical details
CVE-2026-69658 is a cleartext transmission vulnerability in the Ebyte NE2-D11 web management interface, where MQTT credentials and control traffic are sent unencrypted over the network. The root cause is inadequate protection of sensitive communications; the device fails to enforce transport-layer encryption (TLS/SSL) for authentication and session-related information. An attacker with network-level access can passively intercept packets to capture credentials and session tokens, or actively impersonate the device or authenticated users. No authentication or user interaction is required; exploitation works on unpatched firmware FW-9167-0-11. Ebyte acknowledged the vulnerability and indicated a patch was under development, but has not provided status updates or released a fix to CISA.
Affected products
- Ebyte NE2-D11 FW-9167-0-11
Timeline
- 2026-08-25: disclosed
- 2026-08-28: advisory