CVE-2026-73125

Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.

  • Published Aug 28, 2026
  • CVSS 9.3 critical
  • 0.8% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-73125 at the National Vulnerability Database