Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-76179: Ebyte gateway web interface token can be stolen and reused
CVE-2026-76179 · published 7 days ago
Summary
Ebyte gateway devices store their web‑management login tokens in a way that can be seen by someone who can view a user’s session data. If an attacker captures that token, they can pretend to be the logged‑in user and control the device. Protect the devices by applying the vendor’s update or changing the configuration to secure session handling, and limit network access to the management interface.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ebyte | ebyte na111-m firmware | 9013-2-17 |
Original advisory text
Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings
An improper protection of authentication tokens vulnerability exists in
certain Ebyte gateway products. Authentication tokens used by the web
management interface are insufficiently protected during client-side
session handling, which may allow an attacker with access to exposed
session information to obtain and reuse a valid token. Successful
exploitation could allow an attacker to impersonate an authenticated
user and gain unauthorized access to device management functionality.
certain Ebyte gateway products. Authentication tokens used by the web
management interface are insufficiently protected during client-side
session handling, which may allow an attacker with access to exposed
session information to obtain and reuse a valid token. Successful
exploitation could allow an attacker to impersonate an authenticated
user and gain unauthorized access to device management functionality.
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-598Use of HTTP Request With Sensitive Query String
Timeline
Published27 Aug 2026
Updated3 Sep 2026
First seen28 Aug 2026
Monitor software like this
Free during beta