ZeroHour

CVE-2026-73819

Authentication Bypass in Ebyte NA111-M Configuration Utility

CVSS 4.0
9.3 critical
EPSS
<1%p43
Published
()
Modified
AI analysis

The vendor configuration utility for the Ebyte NA111-M grants access to administrative functions without verifying the operator's identity under certain credential conditions, an issue classified as weak authentication (CWE-1390). An unauthenticated attacker positioned on the adjacent network can reach the utility and invoke these administrative functions without valid credentials. By doing so, the attacker can modify critical device settings or change access credentials, which could lock legitimate administrators out of the device. Deployments of the affected Ebyte product in which the configuration interface is reachable from an adjacent network are at risk. No public proof-of-concept, CISA KEV listing, or confirmed exploitation is known; EPSS currently estimates only a 0.5% probability of exploitation in the next 30 days, although the CVSS 4.0 score of 9.3 (critical) reflects high potential impact.

What to do: Restrict access to the NA111-M's configuration utility to trusted management segments (e.g., VLANs, ACLs, or firewall rules) so that adjacent-network attackers cannot reach the interface, and monitor devices for unexpected configuration or credential changes. Check the CISA ICS-CERT advisory and Ebyte's release notes for patched firmware or configuration-utility versions, and apply the vendor's fix as soon as it is identified. If remote administration is not required, disable or firewall the configuration interface until an update is applied.

Affected
Ebyte NA111-M (vendor configuration utility)
Estimated exposure
unknown (no install-base, active-install, or internet-exposure scan data available for the Ebyte NA111-M) — No public scan counts, firmware install-base figures, or deployment statistics were provided for this product, so the number of affected installations cannot be estimated with confidence.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing legitimate administrators from managing the device.

Weakness
CWE-1390
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Ebyte NA111-M

CISA reports 13 vulnerabilities, including CVSS 9.8 missing-authentication flaws, in Ebyte NA111-M firmware that allow full device compromise.

CISA published ICS advisory ICSA-26-239-05 for Ebyte NA111-M firmware 9013-2-17, listing 13 vulnerabilities tracked from CVE-2026-73125 through CVE-2026-77977. The issues include missing authentication for critical functions, GET requests with sensitive query strings, cross-site request forgery, improper restriction of excessive authentication attempts, and missing authorization. The vendor-assessed CVSS v3 score is 9.8, and successful exploitation could allow an attacker to fully compromise the device. No remediation details are included in the summary text.