ZeroHour

CVE-2026-73809

Cleartext Transmission in Ebyte NA111-M Gateway Web Interface Exposes Credentials

CVSS 4.0
8.7 high
EPSS
<1%p6
Published
()
Modified
AI analysis

CVE-2026-73809 is a cleartext transmission flaw (CWE-319) in the web management interface of certain Ebyte gateway products, with the NA111-M model named in related coverage, that fails to protect sensitive communications with transport-layer encryption. It is triggered when a user interacts with the device's management web pages over an unencrypted connection, allowing anyone positioned to observe network traffic to intercept authentication or session-related information. An attacker who captures this data gains disclosure of sensitive information and can use it to obtain unauthorized access to the device's management functionality, reflected in the high confidentiality impact in the 8.7 (High) CVSS 4.0 score. Operators of affected Ebyte gateways, typically deployed in industrial and IoT networking environments, are exposed, although the available data specifies no version range. There is currently no evidence of active exploitation: the flaw is not in CISA's Known Exploited Vulnerabilities catalog, has no public proof-of-concept, and carries a low EPSS probability of 0.2%.

What to do: Do not expose the device's web management interface to untrusted networks; access it only over a trusted LAN, VPN, or encrypted tunnel, and restrict management access with firewall/ACL rules. Check the Ebyte advisory and the associated CISA ICS advisory for the full list of affected models and fixed firmware, and apply the vendor's update when available. Because credentials may have been captured in cleartext, change device management passwords after enabling protected access.

Affected
Ebyte NA111-M gateway
Ebyte other gateway products covered by the advisory (described as 'certain Ebyte gateway products')
Estimated exposure
unknown — no install-base, market-share, or internet-exposure scan figures available for Ebyte NA111-M gateways — The source data provides no active-install counts or public scan data for Ebyte gateways, and serial-to-Ethernet/OT gateways of this type are commonly managed on internal networks rather than exposed to the internet, so no reliable order…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful exploitation could result in disclosure of sensitive information and unauthorized access to device management functionality.

Weakness
CWE-319
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Ebyte NA111-M

CISA reports 13 vulnerabilities, including CVSS 9.8 missing-authentication flaws, in Ebyte NA111-M firmware that allow full device compromise.

CISA published ICS advisory ICSA-26-239-05 for Ebyte NA111-M firmware 9013-2-17, listing 13 vulnerabilities tracked from CVE-2026-73125 through CVE-2026-77977. The issues include missing authentication for critical functions, GET requests with sensitive query strings, cross-site request forgery, improper restriction of excessive authentication attempts, and missing authorization. The vendor-assessed CVSS v3 score is 9.8, and successful exploitation could allow an attacker to fully compromise the device. No remediation details are included in the summary text.