ZeroHour

CVE-2026-76133

Deprecated Hashing Algorithm Weakens Authentication in Ebyte NA111-M

CVSS 4.0
9.3 critical
EPSS
<1%p33
Published
()
Modified
AI analysis

CVE-2026-76133 describes a use of a deprecated hashing algorithm (CWE-327) in an authentication-related operation on an Ebyte product, identified in related coverage as the NA111-M. The flaw is triggered when an attacker is in a position to manipulate or predict the authentication exchange, at which point the weak hash construction undermines the assurance the mechanism is meant to provide. An attacker who exploits this may achieve unauthorized access to the device or its services; the CVSS 4.0 score of 9.3 (critical) reflects network-based, unauthenticated exploitation with potentially high confidentiality, integrity, and availability impact. Users and operators of Ebyte NA111-M devices, which are typically deployed in IoT and industrial connectivity roles, are affected. Exploitation has not been observed: there is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.

What to do: Check whether NA111-M modules in your environment expose their authentication interfaces to untrusted or internet-facing networks, and restrict access with firewalling or network segmentation in the meantime. Watch for the CISA ICS-CERT advisory and vendor guidance for patched firmware, and upgrade as soon as a fixed version is published; avoid relying on the affected authentication exchange for security-critical access controls until then.

Affected
Ebyte NA111-M
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker can manipulate or predict the authentication exchange, the weak construction may reduce the assurance provided by the authentication mechanism and facilitate unauthorized access.

Weakness
CWE-327
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Ebyte NA111-M

CISA reports 13 vulnerabilities, including CVSS 9.8 missing-authentication flaws, in Ebyte NA111-M firmware that allow full device compromise.

CISA published ICS advisory ICSA-26-239-05 for Ebyte NA111-M firmware 9013-2-17, listing 13 vulnerabilities tracked from CVE-2026-73125 through CVE-2026-77977. The issues include missing authentication for critical functions, GET requests with sensitive query strings, cross-site request forgery, improper restriction of excessive authentication attempts, and missing authorization. The vendor-assessed CVSS v3 score is 9.8, and successful exploitation could allow an attacker to fully compromise the device. No remediation details are included in the summary text.