Junglewise Threat Intelligence

CVE-2026-75548: Ebyte NE2-D11 clickjacking in web management interface

CVE-2026-75548 · Severity: medium · CVSS 5.4 · Published 2026-08-28

Technologies: Ebyte NE2-D11. Vendors: Ebyte.

Executive brief

The Ebyte NE2-D11 is an industrial gateway device used in critical infrastructure networks. Its web management interface fails to prevent clickjacking attacks, allowing an attacker to trick authenticated administrators into making unintended configuration changes or disruptive actions via a malicious webpage. This could lead to unauthorized device reconfiguration or denial of service in critical manufacturing or energy operations.

Technical details

The vulnerability is an improper restriction of rendered UI layers or frames (clickjacking/UI redressing). The web management interface does not implement X-Frame-Options or Content-Security-Policy headers to prevent the interface from being embedded in external frames. An unauthenticated attacker can craft a webpage that frames the device's management interface and overlay transparent clickable elements to trick an authenticated administrator into performing unintended actions. The attack requires the administrator to be authenticated to the device and to visit the attacker's malicious webpage. No patch has been released; Ebyte acknowledged the vulnerability but has not provided remediation guidance or timelines.

Affected products

  • Ebyte NE2-D11 Firmware FW-9167-0-11

Timeline

  • 2026-08-25: disclosed
  • 2026-08-28: advisory

References

Related threats