AI analysis
The web management interface of the Ebyte NA111-M does not restrict itself from being rendered inside an external frame, a frame-injection flaw classified as CWE-1021 (improper restriction of rendered UI layers or frames), enabling classic clickjacking/UI-redress attacks. An unauthenticated remote attacker can host a crafted webpage that, when visited by an already-authenticated administrator, invisibly overlays or embeds the device's management interface so that the admin's clicks trigger unintended configuration changes or disruptive actions on the device. Per the CVSS 4.0 vector (UI:P, VC:L/VI:L/VA:N), the attack requires user interaction and yields limited confidentiality and integrity impact rather than availability loss. Only deployments of the affected Ebyte device web management interface are impacted, and exploitation depends on the administrator's browser being able to reach both the attacker's page and the device UI. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.
What to do: No fixed version is specified in the available data, so monitor Ebyte (and the ICS CERT advisory) for a firmware update that adds frame-ancestors/X-Frame-Options protection to the web interface. As interim mitigations, log out of the device management UI before browsing untrusted websites, restrict access to the management interface to trusted management networks, and avoid multitasking between the device UI and other web pages in the same browser session.
Affected
| Ebyte NA111-M device web management interface | — |
Estimated exposure
unknown — plausibly thousands of deployed units of this single low-cost industrial module, but no public install-base or internet-exposure counts are available — No public sales figures, active-install counts, or internet-facing scan data exist for this single Ebyte model, and the flaw only applies to administrators whose browsers can reach both the device's web UI (typically on a local management…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator into initiating unintended configuration changes or disruptive actions.