Executive brief
The Ebyte NE2-D11 is a network gateway device used in critical infrastructure environments to manage industrial control systems. An unauthenticated attacker who gains access to a configuration export file can recover plaintext administrative credentials and use them to take control of the device or other systems with identical credentials, potentially disrupting critical operations or compromising sensitive data.
Technical details
The vulnerability is an insufficiently protected credentials exposure (CWE-522) where administrative credentials and sensitive configuration data are exported in plaintext without adequate encryption or obfuscation. An unauthenticated attacker on an adjacent network who can obtain the exported configuration file can recover valid credentials and use them to gain unauthorized administrative access. The vulnerability affects Ebyte NE2-D11 firmware version FW-9167-0-11, and the attack vector is adjacent network access with no authentication required. No patch is currently available; the vendor acknowledged the issue but has not provided a fix.
Affected products
- Ebyte NE2-D11 FW-9167-0-11
Timeline
- 2026-08-25: disclosed
- 2026-08-31: advisory