Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-71187: Ebyte device can be logged into without a password
CVE-2026-71187 · published 7 days ago
Summary
The Ebyte hardware’s login process can be copied, allowing anyone to send a valid login request and gain administrator rights. This could let attackers change settings, view data, or control the device. Apply the latest firmware or contact the vendor for a fix as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ebyte | ebyte na111-m firmware | 9013-2-17 |
Original advisory text
Ebyte NA111-M Use of Client-Side Authentication
The Ebyte device relies on client side authentication logic that can be
reproduced by unauthenticated users. An attacker may generate valid
authentication requests and bypass authentication to obtain
administrative access to the device.
reproduced by unauthenticated users. An attacker may generate valid
authentication requests and bypass authentication to obtain
administrative access to the device.
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-603Use of Client-Side Authentication
Timeline
Published27 Aug 2026
Updated3 Sep 2026
First seen28 Aug 2026
Monitor software like this
Free during beta