Junglewise Threat Intelligence

CVE-2026-73819: Ebyte NE2-D11 missing authentication in management interface

CVE-2026-73819 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

The Ebyte NE2-D11 is a network gateway device used in critical infrastructure (manufacturing and energy) to manage communications and device configuration. An unauthenticated attacker on the network can bypass authentication checks in the web management interface to gain administrative access, allowing them to modify device settings, access sensitive information, or disable the device entirely.

Technical details

The vulnerability is a missing authentication control (CWE-306) in the web management interface that does not consistently verify user identity before granting access to administrative functions. The flaw affects the vendor configuration utility and allows unauthenticated remote attackers on the network to perform privileged operations without credentials. An attacker can exploit this to access sensitive configuration, modify device settings, change administrative credentials, and disrupt device operation. Ebyte acknowledged the vulnerability and indicated a patch was under development, but has not provided status or availability information as of the advisory date.

Affected products

  • Ebyte NE2-D11 Firmware FW-9167-0-11

Timeline

  • 2026-08-25: disclosed
  • 2026-08-31: advisory

References

Related threats