Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-71187: Ebyte device can be logged into without a password

CVE-2026-71187 · published 7 days ago
Summary

The Ebyte hardware’s login process can be copied, allowing anyone to send a valid login request and gain administrator rights. This could let attackers change settings, view data, or control the device. Apply the latest firmware or contact the vendor for a fix as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ebyte ebyte na111-m firmware 9013-2-17
Original advisory text
Ebyte NA111-M Use of Client-Side Authentication
The Ebyte device relies on client side authentication logic that can be
reproduced by unauthenticated users. An attacker may generate valid
authentication requests and bypass authentication to obtain
administrative access to the device.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-603Use of Client-Side Authentication
Timeline
Published27 Aug 2026
Updated3 Sep 2026
First seen28 Aug 2026
Sources
CVE-2026-71187 · MITRE
Monitor software like this
Free during beta