Executive brief
Ebyte NE2-D11 is an industrial gateway used in critical manufacturing and energy infrastructure. Its web management interface transmits authentication and session information without encryption, allowing attackers on the network to intercept credentials and gain unauthorized access to device management functions. Successful exploitation could compromise device configuration, disrupt operations, and enable further attacks on critical infrastructure.
Technical details
This vulnerability (CWE-319) exists in the web management interface of the Ebyte NE2-D11 gateway, which fails to enforce transport-layer encryption (HTTPS) for sensitive communications. The affected firmware version FW-9167-0-11 transmits authentication tokens and session information in cleartext over the network. An attacker with network access (AV:N, AC:L, PR:N, UI:N) can passively intercept these communications to obtain valid credentials or session tokens, leading to unauthorized administrative access. The vendor acknowledged the issue but has not released patches; remediation requires user outreach to Ebyte for patch availability or network-level controls to restrict access to the management interface.
Affected products
- Ebyte NE2-D11 FW-9167-0-11
Timeline
- 2026-08-25: disclosed
- 2026-08-28: advisory: CVE-2026-73809 published