Junglewise Threat Intelligence

CVE-2026-73839: Ebyte NE2-D11 plaintext credentials in management interface

CVE-2026-73839 · Severity: medium · CVSS 4.6 · Published 2026-08-28

Technologies: Ebyte NE2-D11. Vendors: Ebyte.

Executive brief

The Ebyte NE2-D11 network gateway device stores and displays administrative credentials in plaintext within its web-based management interface. An attacker with physical access to a device screen or network visibility into management traffic could observe and capture these credentials, leading to unauthorized administrative access and full device compromise.

Technical details

This vulnerability (CWE-522: Insufficiently Protected Credentials) occurs when the Ebyte NE2-D11 management interface fails to mask or encrypt administrative credentials displayed in the web UI. The plaintext exposure allows attackers with physical access to the device screen or the ability to monitor network traffic to the management interface to directly read valid credentials. No authentication or user interaction is required to observe the credentials once the management interface is accessed. A patch is under development but has not yet been released by Ebyte.

Affected products

  • Ebyte NE2-D11 Firmware FW-9167-0-11

Timeline

  • 2026-08-25: disclosed
  • 2026-08-28: advisory

References

Related threats