Junglewise Threat Intelligence

CVE-2026-76179: Ebyte NE2-D11 improper authentication token protection

CVE-2026-76179 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Technologies: Ebyte NE2-D11. Vendors: Ebyte.

Executive brief

The Ebyte NE2-D11 is an industrial gateway device used to manage critical infrastructure in manufacturing and energy sectors. A flaw in how authentication tokens are handled allows attackers with network access to steal and reuse session tokens, gaining unauthorized access to device management functions. This could enable an attacker to reconfigure the device, steal sensitive data, or shut down operations without requiring legitimate credentials.

Technical details

The vulnerability is an improper protection of authentication tokens (CWE-613) in the web management interface of the Ebyte NE2-D11 gateway. Authentication tokens used for client-side session handling are insufficiently protected, allowing an attacker with access to network traffic or session information to capture and replay valid tokens. The flaw is part of a broader authentication weakness (related to CWE-306: Missing Authentication for Critical Function) that also involves client-side authentication logic. An attacker with network access can intercept tokens and impersonate an authenticated administrator. No patch has been released; the vendor acknowledged the issue but has not provided remediation guidance.

Affected products

  • Ebyte NE2-D11 FW-9167-0-11

Timeline

  • 2026-08-28: disclosed
  • 2026-08-25: advisory: CISA ICSA-26-237-06

References

Related threats