ZeroHour

CVE-2026-76940

Missing Rate Limiting (CWE-307) in Ebyte NA111-M Enables Automated Password Attacks

CVSS 4.0
8.7 high
EPSS
<1%p29
Published
()
Modified
AI analysis

CVE-2026-76940 is a CWE-307 weakness (improper restriction of excessive authentication attempts) in the Ebyte NA111-M device, which enforces neither rate limiting nor account lockout on repeated authentication attempts. A remote, unauthenticated attacker can therefore automate repeated login guesses over the network (CVSS 4.0: network vector, low complexity, no privileges or user interaction required). If a guess succeeds, the attacker gains valid authenticated access to the device, with high confidentiality impact per the CVSS scoring (VI:N/VA:N, VC:H). Exposure is limited to deployments that rely on password-based authentication and whose authentication interface is reachable by an attacker, such as internet-exposed or flat-network installations. No public proof-of-concept, KEV listing, or confirmed exploitation is known; EPSS currently estimates only a ~0.4% probability of exploitation within 30 days.

What to do: Until vendor guidance or a firmware fix is published, restrict reachability of the device's authentication interface (firewall ACLs, VPN-only access), avoid exposing password-based login directly to the internet, and ensure a strong unique password is in use. Check whether your deployments authenticate via passwords and review device logs for signs of automated guessing; monitor the vendor and CISA ICS advisories for updated firmware or mitigations.

Affected
Ebyte NA111-M
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated authentication attacks against deployments that rely on password based authentication.

Weakness
CWE-307
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Ebyte NA111-M

CISA reports 13 vulnerabilities, including CVSS 9.8 missing-authentication flaws, in Ebyte NA111-M firmware that allow full device compromise.

CISA published ICS advisory ICSA-26-239-05 for Ebyte NA111-M firmware 9013-2-17, listing 13 vulnerabilities tracked from CVE-2026-73125 through CVE-2026-77977. The issues include missing authentication for critical functions, GET requests with sensitive query strings, cross-site request forgery, improper restriction of excessive authentication attempts, and missing authorization. The vendor-assessed CVSS v3 score is 9.8, and successful exploitation could allow an attacker to fully compromise the device. No remediation details are included in the summary text.