AI analysis
CVE-2026-76133 describes a use of a deprecated hashing algorithm (CWE-327) in an authentication-related operation on an Ebyte product, identified in related coverage as the NA111-M. The flaw is triggered when an attacker is in a position to manipulate or predict the authentication exchange, at which point the weak hash construction undermines the assurance the mechanism is meant to provide. An attacker who exploits this may achieve unauthorized access to the device or its services; the CVSS 4.0 score of 9.3 (critical) reflects network-based, unauthenticated exploitation with potentially high confidentiality, integrity, and availability impact. Users and operators of Ebyte NA111-M devices, which are typically deployed in IoT and industrial connectivity roles, are affected. Exploitation has not been observed: there is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.
What to do: Check whether NA111-M modules in your environment expose their authentication interfaces to untrusted or internet-facing networks, and restrict access with firewalling or network segmentation in the meantime. Watch for the CISA ICS-CERT advisory and vendor guidance for patched firmware, and upgrade as soon as a fixed version is published; avoid relying on the affected authentication exchange for security-critical access controls until then.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker can manipulate or predict the authentication exchange, the weak construction may reduce the assurance provided by the authentication mechanism and facilitate unauthorized access.