ZeroHour

CVE-2026-76179

Improperly Protected Auth Tokens in Ebyte Gateway Web Interface (incl. NA111-M)

CVSS 4.0
9.3 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-76179 is an improper protection of authentication tokens flaw (CWE-598) in the web management interface of certain Ebyte gateway products, where session tokens are insufficiently protected during client-side session handling. An attacker who can obtain exposed session information (for example from logs, URLs, or other artifacts where the token is visible) can reuse a valid token to hijack the session. Successful exploitation lets the attacker impersonate an authenticated user and gain unauthorized access to device management functionality, with high impact to confidentiality, integrity, and availability per the 9.3 critical CVSS 4.0 score. Operators of the affected Ebyte gateways — including the NA111-M model cited in related coverage — are in scope, though no specific vulnerable version ranges are published. There is currently no known public proof-of-concept, it is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at roughly 0.4%.

What to do: No fixed version is published in the available data, so check with Ebyte/EBYTE support for a firmware update for your gateway model (e.g., NA111-M) and apply it when available. In the meantime, do not expose the device's web management interface to the internet or untrusted networks, use HTTPS where supported, and avoid sharing or bookmarking URLs that contain session tokens. Review access logs and active sessions for signs of token reuse, and revoke/re-establish sessions after updating.

Affected
Ebyte Gateway products (web management interface), including the NA111-M gateway
Estimated exposure
unknown (no public install-base figures or internet-exposure scan data for Ebyte gateways) — No public active-install counts or exposure scans exist for these devices; Ebyte's low-cost industrial IoT gateways are typically deployed on operational/internal networks behind firewalls, so internet-exposed instances are likely limited…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality.

Weakness
CWE-598
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Ebyte NA111-M

CISA reports 13 vulnerabilities, including CVSS 9.8 missing-authentication flaws, in Ebyte NA111-M firmware that allow full device compromise.

CISA published ICS advisory ICSA-26-239-05 for Ebyte NA111-M firmware 9013-2-17, listing 13 vulnerabilities tracked from CVE-2026-73125 through CVE-2026-77977. The issues include missing authentication for critical functions, GET requests with sensitive query strings, cross-site request forgery, improper restriction of excessive authentication attempts, and missing authorization. The vendor-assessed CVSS v3 score is 9.8, and successful exploitation could allow an attacker to fully compromise the device. No remediation details are included in the summary text.