Junglewise Threat Intelligence

CVE-2026-76940: Ebyte NE2-D11 missing authentication and excessive authentication attempts

CVE-2026-76940 · Severity: high · CVSS 7.5 · Published 2026-08-28

Technologies: Ebyte NE2-D11. Vendors: Ebyte.

Executive brief

The Ebyte NE2-D11 is an industrial gateway device used to manage critical infrastructure in manufacturing and energy sectors. The device contains multiple authentication bypass vulnerabilities that allow attackers to gain unauthorized administrative access without credentials and perform brute-force password attacks without rate limiting. Exploitation could result in unauthorized configuration changes, data theft, session hijacking, and operational disruption in essential infrastructure.

Technical details

The Ebyte NE2-D11 firmware (FW-9167-0-11) contains multiple critical flaws: (1) missing authentication in web management functions (CVE-2026-73125), allowing unauthenticated remote attackers to access sensitive configuration via network requests; (2) cleartext transmission of sensitive data including authentication credentials (CVE-2026-73809), enabling network-based interception without encryption; (3) plaintext exposure of administrative credentials in the management interface (CVE-2026-73839); (4) client-side authentication logic that attackers can replicate to forge valid requests (CVE-2026-71187); and (5) no rate limiting on authentication attempts (CVE-2026-76940), enabling brute-force attacks. The vulnerabilities are network-reachable and require no authentication or user interaction. Patches are under development but not yet available; mitigation requires network segmentation and access controls.

Affected products

  • Ebyte NE2-D11 Firmware FW-9167-0-11

Timeline

  • 2026-08-25: disclosed
  • 2026-08-28: advisory: CISA ICSA-26-237-06 published

References

Related threats