Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-73819: Ebyte NE2-D11 allows admin changes without proper login
CVE-2026-73819 · published 3 days ago
Summary
The configuration tool for the Ebyte NE2-D11 lets anyone on the same network change important settings or reset passwords without proving who they are. This could let an attacker lock out legitimate managers or alter the device’s behavior. Protect it by restricting network access to the tool and require strong authentication before making changes.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ebyte | ebyte ne2-d11 firmware | FW-9167-0-11 |
| ebyte | ebyte na111-m firmware | 9013-2-17 |
Original advisory text
The affected Ebyte
product's vendor configuration utility permits access to administrative
functions without verifying the operator's identity under certain
credential conditions. An unauthenti...
The affected Ebyte
product's vendor configuration utility permits access to administrative
functions without verifying the operator's identity under certain
credential conditions. An unauthenticated attacker on the adjacent
network could modify critical settings or change access credentials,
potentially preventing legitimate administrators from managing the
device.
product's vendor configuration utility permits access to administrative
functions without verifying the operator's identity under certain
credential conditions. An unauthenticated attacker on the adjacent
network could modify critical settings or change access credentials,
potentially preventing legitimate administrators from managing the
device.
Severity
9.3
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-1390Weak Authentication
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Monitor software like this
Free during beta