ZeroHour

CVE-2026-71187

large

Client-side authentication bypass in Ebyte NA111-M device

CVSS 4.0
9.3 critical
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-71187 is an authentication bypass (CWE-603, use of client-side authentication) in the Ebyte device identified in related coverage as the NA111-M, where the login check is performed by logic running on the client rather than being enforced and verified on the device itself. Because that client-side logic can be reproduced, an unauthenticated attacker with network reachability to the device can generate valid authentication requests and gain administrative access without knowing any credentials. Per the CVSS 4.0 base score of 9.3 (critical), the attacker obtains high confidentiality, integrity, and availability impact on the device, e.g. by reconfiguring it or disrupting its operation. Operators who deploy Ebyte NA111-M units, especially where the device's network-facing interface is reachable from an untrusted LAN segment or from the internet, are affected; the available data does not list affected firmware versions or confirm whether other Ebyte models are impacted. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS assigns a 0.5% probability of exploitation in the next 30 days (43rd percentile), so no confirmed exploitation is currently known (the CVE was assigned by CISA ICS-CERT, consistent with an industrial/IoT device).

What to do: Do not expose NA111-M management interfaces directly to the internet or to untrusted LAN segments; restrict access with firewall rules or a dedicated management VLAN and review device logs for successful unauthenticated administrative logins. Check Ebyte's advisories for updated firmware addressing CVE-2026-71187 and apply it when released, since a client-side authentication flaw cannot be fully remediated by configuration alone. Follow the CISA ICS-CERT advisory for confirmed affected versions and fixed releases.

Affected
Ebyte NA111-M
Estimated exposure
largeroughly 10k-100k deployed NA111 units (estimate), with only a small fraction likely directly internet-exposed — No install-base, plugin-install, or internet-scan counts were provided, so this rests on Ebyte's position as a high-volume IoT/serial-to-network module vendor and on the typical embedded, LAN-side deployment pattern of such modules, which…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.

Weakness
CWE-603
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Ebyte NA111-M

CISA reports 13 vulnerabilities, including CVSS 9.8 missing-authentication flaws, in Ebyte NA111-M firmware that allow full device compromise.

CISA published ICS advisory ICSA-26-239-05 for Ebyte NA111-M firmware 9013-2-17, listing 13 vulnerabilities tracked from CVE-2026-73125 through CVE-2026-77977. The issues include missing authentication for critical functions, GET requests with sensitive query strings, cross-site request forgery, improper restriction of excessive authentication attempts, and missing authorization. The vendor-assessed CVSS v3 score is 9.8, and successful exploitation could allow an attacker to fully compromise the device. No remediation details are included in the summary text.