TL;DR
CISA disclosed 11 Ebyte NE2-D11 vulnerabilities on August 25, 2026. Four carry a critical 9.8 CVSS score. Attackers could seize full control of the gateway, and no patch is confirmed available yet.
- Total: 11 CVEs
- Severity: 4 Critical · 5 High · 2 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-73125
- Action: Apply the latest security updates now
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-73125 | 9.8 | NA111-M Missing Authentication for Critical Function | Not exploited |
| CVE-2026-71187 | 9.8 | NA111-M Use of Client-Side Authentication | Not exploited |
| CVE-2026-76179 | 9.8 | NA111-M Use of GET Request Method With Sensitive Query Strings | Not exploited |
| CVE-2026-69658 | 9.8 | NA111-M Cleartext Transmission of Sensitive Information | Not exploited |
| CVE-2026-75814 | 8.8 | NA111-M Cross-Site Request Forgery | Not exploited |
| CVE-2026-73809 | 7.5 | NA111-M Cleartext Transmission of Sensitive Information | Not exploited |
| CVE-2026-76940 | 7.5 | NA111-M Improper Restriction of Excessive Authentication Attempts | Not exploited |
| CVE-2026-75813 | 7.5 | NE2-D11 Missing Authorization | Not exploited |
Why These Ebyte NE2-D11 Vulnerabilities Matter
The NE2-D11 is an industrial IoT gateway from China-based Ebyte. It links serial and MQTT devices in factories and energy sites. CISA lists the affected sectors as critical manufacturing and energy, deployed worldwide.
These Ebyte NE2-D11 vulnerabilities stack up fast. Researcher Jithin Nambiar reported the full set to CISA. Because many flaws need no login, the risk to exposed gateways is high.
How the Attacks Work
Several bugs share one theme: weak authentication. CISA warns the device does not consistently enforce authentication before granting access to administrative functionality.
As a result, a remote attacker can read config, change settings, or knock the device offline.
Other flaws widen the gap. The gateway relies on client-side authentication logic that attackers can copy. It also sends MQTT credentials and control traffic in cleartext. Consequently, network snoopers can impersonate devices and hijack sessions.
Is It Being Exploited?
No exploitation in the wild has been confirmed. CISA states no known public exploitation has been reported. Likewise, no public proof-of-concept exists at this time.
Affected Versions
The advisory names NE2-D11 firmware version FW-9167-0-11. Users on that build should treat every internet-facing gateway as at risk.
Patch and Mitigation Steps
No fix is confirmed. CISA says Ebyte acknowledged the reports and indicated a patch was under development. However, the vendor has not responded to later coordination requests, so users should contact Ebyte directly.
Meanwhile, follow CISA’s defensive advice in the official ICS advisory ICSA-26-237-06. Keep control devices off the public internet. Place them behind firewalls, and use a VPN for remote access.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!