AI analysis
CVE-2026-71187 is an authentication bypass (CWE-603, use of client-side authentication) in the Ebyte device identified in related coverage as the NA111-M, where the login check is performed by logic running on the client rather than being enforced and verified on the device itself. Because that client-side logic can be reproduced, an unauthenticated attacker with network reachability to the device can generate valid authentication requests and gain administrative access without knowing any credentials. Per the CVSS 4.0 base score of 9.3 (critical), the attacker obtains high confidentiality, integrity, and availability impact on the device, e.g. by reconfiguring it or disrupting its operation. Operators who deploy Ebyte NA111-M units, especially where the device's network-facing interface is reachable from an untrusted LAN segment or from the internet, are affected; the available data does not list affected firmware versions or confirm whether other Ebyte models are impacted. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS assigns a 0.5% probability of exploitation in the next 30 days (43rd percentile), so no confirmed exploitation is currently known (the CVE was assigned by CISA ICS-CERT, consistent with an industrial/IoT device).
What to do: Do not expose NA111-M management interfaces directly to the internet or to untrusted LAN segments; restrict access with firewall rules or a dedicated management VLAN and review device logs for successful unauthenticated administrative logins. Check Ebyte's advisories for updated firmware addressing CVE-2026-71187 and apply it when released, since a client-side authentication flaw cannot be fully remediated by configuration alone. Follow the CISA ICS-CERT advisory for confirmed affected versions and fixed releases.
Estimated exposure
largeroughly 10k-100k deployed NA111 units (estimate), with only a small fraction likely directly internet-exposed — No install-base, plugin-install, or internet-scan counts were provided, so this rests on Ebyte's position as a high-volume IoT/serial-to-network module vendor and on the typical embedded, LAN-side deployment pattern of such modules, which…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.