Junglewise Threat Intelligence

CVE-2026-75813: Ebyte NE2-D11 missing authorization in configuration endpoints

CVE-2026-75813 · Severity: high · CVSS 7.5 · Published 2026-08-28

Technologies: Ebyte NE2-D11. Vendors: Ebyte.

Executive brief

The Ebyte NE2-D11 is a network gateway device used in critical infrastructure environments. Certain configuration endpoints lack proper authorization checks, allowing unauthorized users to access or modify sensitive device settings without authentication. This could result in full compromise of device functionality, including disclosure of credentials, disruption of operations, and unauthorized administrative access.

Technical details

This vulnerability is a missing authentication issue (CWE-306) affecting the Ebyte NE2-D11 web management interface. The device fails to consistently enforce authentication before granting access to critical administrative functions, allowing unauthenticated remote attackers to directly access sensitive configuration endpoints over the network. An attacker can read sensitive configuration data, modify device settings, or disrupt device availability without needing valid credentials. The vulnerability is exacerbated by related issues including cleartext transmission of sensitive data, exposed credentials in the management interface, and client-side authentication logic that can be bypassed. Ebyte acknowledged the vulnerability and indicated a patch was under development, but has not provided an update or confirmed patch availability.

Affected products

  • Ebyte NE2-D11 Firmware FW-9167-0-11

Timeline

  • 2026-08-25: disclosed
  • 2026-08-28: advisory

References

Related threats