Executive brief
The Ebyte NE2-D11 is a network gateway device used in critical infrastructure environments to manage and control industrial systems. The device uses a deprecated hashing algorithm in its authentication mechanism that can be predicted or manipulated by an attacker, allowing them to bypass authentication and gain unauthorized administrative access, modify configurations, and disrupt operations across critical manufacturing and energy sectors worldwide.
Technical details
The vulnerability stems from the use of a deprecated hashing algorithm in authentication-related operations within the Ebyte NE2-D11 firmware (FW-9167-0-11). The weak cryptographic construction allows attackers to predict or manipulate the authentication exchange, reducing the security assurance of the authentication mechanism. An attacker with network access can exploit this to bypass authentication controls without requiring valid credentials or user interaction, potentially gaining full administrative access to the device. Additionally, the advisory notes multiple related authentication weaknesses (CVE-2026-73125, CVE-2026-71187) including missing authentication enforcement and client-side authentication bypass. Ebyte has indicated a patch is under development but has not provided status updates or availability information to CISA.
Affected products
- Ebyte NE2-D11 Firmware FW-9167-0-11
Timeline
- 2026-08-25: disclosed
- 2026-08-31: advisory