Missing Rate Limiting (CWE-307) in Ebyte NA111-M Enables Automated Password Attacks
AI analysis
CVE-2026-76940 is a CWE-307 weakness (improper restriction of excessive authentication attempts) in the Ebyte NA111-M device, which enforces neither rate limiting nor account lockout on repeated authentication attempts. A remote, unauthenticated attacker can therefore automate repeated login guesses over the network (CVSS 4.0: network vector, low complexity, no privileges or user interaction required). If a guess succeeds, the attacker gains valid authenticated access to the device, with high confidentiality impact per the CVSS scoring (VI:N/VA:N, VC:H). Exposure is limited to deployments that rely on password-based authentication and whose authentication interface is reachable by an attacker, such as internet-exposed or flat-network installations. No public proof-of-concept, KEV listing, or confirmed exploitation is known; EPSS currently estimates only a ~0.4% probability of exploitation within 30 days.
What to do: Until vendor guidance or a firmware fix is published, restrict reachability of the device's authentication interface (firewall ACLs, VPN-only access), avoid exposing password-based login directly to the internet, and ensure a strong unique password is in use. Check whether your deployments authenticate via passwords and review device logs for signs of automated guessing; monitor the vendor and CISA ICS advisories for updated firmware or mitigations.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.