AI analysis
CVE-2026-75814 is a cross-site request forgery (CWE-352) weakness in the web management interface of the Ebyte NA111-M device, which does not adequately verify the origin or authenticity of the requests it accepts. An unauthenticated remote attacker triggers the flaw by persuading an administrator who is already logged into the interface to visit a crafted web page, causing the victim's browser to silently submit forged requests. Successful exploitation allows unauthorized configuration changes or a denial-of-service condition that disrupts device availability, consistent with the 8.6 (High) CVSS 4.0 score, which requires network access, no privileges, and active user interaction. Any organization operating an affected NA111-M device whose management interface is reachable by both administrators and untrusted web content is exposed, although no specific affected version ranges are provided in the available data. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days (7th percentile).
What to do: No fixed firmware version is given in the available data, so check the CISA ICS advisory for CVE-2026-75814 and EBYTE support channels for an updated release and apply it when published. Until then, restrict the NA111-M web management interface to trusted management networks or VPN access, log out of admin sessions when not in use, and avoid browsing untrusted sites while authenticated; review device configuration and logs for unexplained changes.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, causing unauthorized configuration changes or a disruption of device availability.