Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-76133: Ebyte NE2-D11 weak hash lets attackers bypass login

CVE-2026-76133 · published 3 days ago
Summary

The Ebyte NE2-D11 device uses an old, insecure method for checking passwords. This can let a hacker trick the device into thinking they are authorized and gain access. Update the device’s software or replace it with a version that uses a modern, strong password check.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ebyte ebyte ne2-d11 firmware FW-9167-0-11
ebyte ebyte na111-m firmware 9013-2-17
Original advisory text
The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker can manipulate or predict the authentication exchange,...
The affected Ebyte

product
uses a deprecated hashing algorithm in an authentication-related
operation. Under conditions where an attacker can manipulate or predict
the authentication exchange, the weak construction may reduce the
assurance provided by the authentication mechanism and facilitate
unauthorized access.
Severity
9.3 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-327Use of a Broken Cryptographic Algorithm
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Sources
CVE-2026-76133 · MITRE
Monitor software like this
Free during beta