Executive brief
The Ebyte NE2-D11 is an industrial gateway device used in critical infrastructure such as manufacturing and energy sectors. The device's web management interface fails to properly validate the origin and authenticity of requests, allowing an attacker to trick an authenticated administrator into visiting a malicious webpage that silently modifies device configuration or takes the device offline. This could disrupt critical industrial operations or compromise system integrity.
Technical details
This is a cross-site request forgery (CSRF) vulnerability in the Ebyte NE2-D11 web management interface that arises from insufficient verification of request authenticity. The vulnerable component is the web interface which does not validate CSRF tokens or properly enforce same-origin policies on state-changing requests. An attacker can craft a malicious webpage and trick an authenticated administrator into visiting it; when the page loads, it automatically submits forged requests to the device, causing unauthorized configuration changes or availability disruption. The attack requires user interaction (social engineering to visit the malicious page) but does not require authentication on the attacker's side. A patch is reportedly under development but has not been publicly released.
Affected products
- Ebyte NE2-D11 Firmware FW-9167-0-11
Timeline
- 2026-08-25: disclosed: CISA ICS Advisory ICSA-26-237-06 published
- 2026-08-28: other: CVE-2026-75814 published on NVD