TL;DR
The Cybersecurity and Infrastructure Security Agency recently published an advisory identifying multiple Ebyte NA111-M vulnerabilities. These security flaws allow remote attackers to bypass authentication controls and execute unauthorized administrative commands. Network administrators must apply defensive mitigations immediately to isolate affected devices from external access.
- Total: 9 CVEs
- Severity: 4 Critical · 4 High · 1 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-73125
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-73125 | 9.8 | NE2-D11 Missing Authentication for Critical Function | Not exploited |
| CVE-2026-76179 | 9.8 | NE2-D11 Use of GET Request Method With Sensitive Query Strings | Not exploited |
| CVE-2026-71187 | 9.8 | NE2-D11 Use of Client-Side Authentication | Not exploited |
| CVE-2026-69658 | 9.8 | NE2-D11 Cleartext Transmission of Sensitive Information | Not exploited |
| CVE-2026-75814 | 8.8 | NE2-D11 Cross-Site Request Forgery | Not exploited |
| CVE-2026-77977 | 8.1 | NE2-D11 Missing Authentication for Critical Function | Not exploited |
| CVE-2026-76940 | 7.5 | NE2-D11 Improper Restriction of Excessive Authentication Attempts | Not exploited |
| CVE-2026-73809 | 7.5 | NE2-D11 Cleartext Transmission of Sensitive Information | Not exploited |
Why the Vulnerabilities Matter
These security flaws pose severe risks to industrial networks and connected IT environments worldwide. According to CISA, “Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device.” Seven of the disclosed flaws carry critical CVSS base scores of 9.8. Consequently, remote attackers could gain total control over unpatched gateways without valid credentials. Ebyte devices operate globally across critical infrastructure sectors. However, CISA has not published specific deployment numbers. Fortunately, the agency confirmed that “No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.” Additionally, researchers have not released public proof-of-concept exploits.
How the Attacks Work
The vulnerabilities span several architectural weaknesses across the web management interface and configuration utility. For example, CVE-2026-73125 allows unauthenticated remote attackers to access administrative functions directly. Similarly, CVE-2026-71187 involves client-side authentication logic that attackers can easily replicate. Furthermore, CVE-2026-76179 exposes session tokens within GET requests, enabling credential theft. Other flaws include missing request origin verification and cleartext transmission of sensitive MQTT credentials. Together, these weaknesses allow attackers to modify device settings and disrupt service availability.
Affected Versions and Mitigations
Impacted Products
The disclosed Ebyte NA111-M vulnerabilities affect all devices running firmware version 9013-2-17.
Mitigation Steps
Currently, an official patch remains unavailable. The advisory notes that “Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development.” However, the vendor has not provided updates regarding fix availability. Therefore, organizations must implement proactive network defenses. Defenders should place control system devices behind firewalls and eliminate direct internet exposure.