Junglewise Threat Intelligence

CVE-2026-73125: Ebyte NE2-D11 missing authentication in web management interface

CVE-2026-73125 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Technologies: Ebyte NE2-D11. Vendors: Ebyte.

Executive brief

Ebyte NE2-D11 is a network gateway device used in critical manufacturing and energy sectors. The web management interface fails to consistently enforce authentication for administrative functions, allowing unauthenticated attackers to access sensitive configuration, modify device settings, or disrupt device availability without credentials.

Technical details

The vulnerability is a missing authentication flaw (CWE-306) in the web management interface of Ebyte NE2-D11 firmware version FW-9167-0-11. The root cause stems from inconsistent authentication enforcement, with the advisory also documenting related issues including client-side authentication bypass, cleartext credential exposure, and unprotected sensitive communications. An unauthenticated remote attacker on the network can directly access administrative functionality without valid credentials or user interaction. Exploitation leads to unauthorized administrative access, configuration disclosure, modification, and denial of service. Ebyte acknowledged the vulnerabilities but has not provided patches or confirmed patch status.

Affected products

  • Ebyte NE2-D11 FW-9167-0-11

Timeline

  • 2026-08-25: disclosed: CISA advisory ICSA-26-237-06 published
  • 2026-08-28: other: NVD entry created

References

Related threats