ZeroHour

CVE-2026-69658

Cleartext MQTT Credential Exposure in Ebyte NA111-M

CVSS 4.0
9.3 critical
EPSS
<1%p15
Published
()
Modified
AI analysis

The Ebyte NA111-M transmits MQTT credentials and control traffic over the network without encryption, a cleartext transmission flaw (CWE-319). An attacker positioned on the network path — for example, on the same LAN or a listening segment between the device and its MQTT broker — can passively capture these credentials and observe or intercept control messages. With harvested credentials, an attacker can impersonate a legitimate device on the broker, inject or disrupt messaging, and gain high confidentiality, integrity, and availability impact on the affected device (CVSS 4.0 score 9.3). Users of the NA111-M module in industrial or IoT deployments where MQTT traffic crosses untrusted network segments are affected. No public proof-of-concept, known exploitation, or KEV listing exists, and EPSS puts 30-day exploitation probability at about 0.2%.

What to do: Inventory deployments of the NA111-M and identify any that use cleartext MQTT (default port 1883) across untrusted or shared network segments; switch to TLS-encrypted MQTT (port 8883) if the module firmware supports it. Isolate MQTT traffic with network segmentation or firewall rules restricting which hosts can reach the broker, and rotate any MQTT credentials that may have traversed exposed links. Monitor CISA ICS advisories and the vendor's channel for firmware updates addressing cleartext transmission.

Affected
Ebyte NA111-M
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.

Weakness
CWE-319
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Ebyte NA111-M

CISA reports 13 vulnerabilities, including CVSS 9.8 missing-authentication flaws, in Ebyte NA111-M firmware that allow full device compromise.

CISA published ICS advisory ICSA-26-239-05 for Ebyte NA111-M firmware 9013-2-17, listing 13 vulnerabilities tracked from CVE-2026-73125 through CVE-2026-77977. The issues include missing authentication for critical functions, GET requests with sensitive query strings, cross-site request forgery, improper restriction of excessive authentication attempts, and missing authorization. The vendor-assessed CVSS v3 score is 9.8, and successful exploitation could allow an attacker to fully compromise the device. No remediation details are included in the summary text.