Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-76133: Ebyte NE2-D11 weak hash lets attackers bypass login
CVE-2026-76133 · published 3 days ago
Summary
The Ebyte NE2-D11 device uses an old, insecure method for checking passwords. This can let a hacker trick the device into thinking they are authorized and gain access. Update the device’s software or replace it with a version that uses a modern, strong password check.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ebyte | ebyte ne2-d11 firmware | FW-9167-0-11 |
| ebyte | ebyte na111-m firmware | 9013-2-17 |
Original advisory text
The affected Ebyte
product
uses a deprecated hashing algorithm in an authentication-related
operation. Under conditions where an attacker can manipulate or predict
the authentication exchange,...
The affected Ebyte
product
uses a deprecated hashing algorithm in an authentication-related
operation. Under conditions where an attacker can manipulate or predict
the authentication exchange, the weak construction may reduce the
assurance provided by the authentication mechanism and facilitate
unauthorized access.
product
uses a deprecated hashing algorithm in an authentication-related
operation. Under conditions where an attacker can manipulate or predict
the authentication exchange, the weak construction may reduce the
assurance provided by the authentication mechanism and facilitate
unauthorized access.
Severity
9.3
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-327Use of a Broken Cryptographic Algorithm
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Monitor software like this
Free during beta