Ebyte NA111-M

12 known vulnerabilities in Ebyte NA111-M, 6 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-77966 CVSS 8.7 high The affected Ebyte product does not provide separation between limited and administrative management functions. A low privileged…
  • CVE-2026-76133 CVSS 9.3 critical The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker…
  • CVE-2026-73819 CVSS 9.3 critical The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's…
  • CVE-2026-77977 CVSS 7.2 high Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive administrative…
  • CVE-2026-76940 CVSS 8.7 high The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This…
  • CVE-2026-76179 CVSS 9.3 critical An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the…
  • CVE-2026-75814 CVSS 8.6 high The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An…
  • CVE-2026-75548 CVSS 5.3 medium The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An…
  • CVE-2026-73809 CVSS 8.7 high A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface…
  • CVE-2026-73125 CVSS 9.3 critical Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality…
  • CVE-2026-71187 CVSS 9.3 critical The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate…
  • CVE-2026-69658 CVSS 9.3 critical MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may…