CVE-2026-75548
The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator into initiating unintended configuration changes or disruptive actions.
- Published Aug 28, 2026
- CVSS 5.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)