ZeroHour

CVE-2026-76945

moderate

Authentication Bypass via Token Replay in Ebyte Devices

CVSS 4.0
8.7 high
EPSS
<1%p30
Published
()
Modified
AI analysis

The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation (CWE-603), meaning authentication is accepted based on values supplied or controlled by the client rather than verified against an authoritative source. An attacker who can reach the device's authentication mechanism over the network (AV:N, no privileges or user interaction required) can replay a previously captured token or manipulate a presented token to bypass authentication. Successful abuse grants unauthorized access to administrative functionality, with the CVSS base indicating a high impact on confidentiality of the vulnerable system and no integrity or availability impact scored. Any operator of the affected Ebyte device is exposed; the advisory data does not identify the specific model or version range. No public proof-of-concept exists, the issue is not in CISA's KEV, and EPSS assigns a 0.4% (30th percentile) probability of exploitation within 30 days, so no exploitation is currently known.

What to do: Identify which Ebyte device(s) your organization operates and check whether the administrative interface is reachable from untrusted networks; restrict access with firewall ACLs, network segmentation, or a VPN until a vendor fix is available. Monitor the CISA ICS-CERT advisory and Ebyte firmware release channels for the affected model and a patched version, then update promptly — no fixed version numbers are available in the current data. In the interim, consider rotating credentials or sessions and reviewing device logs for unexpected administrative logins.

Affected
Ebyte Affected Ebyte device (specific model not identified in the provided advisory data; assigned by CISA ICS-CERT, indicatin
Estimated exposure
moderate≈1,000–10,000 devices plausibly affected via remotely reachable administrative interfaces (order of thousands; estimate only) — Ebyte is a high-volume supplier of wireless modules and IoT/OT networking devices, but such radios and gateways are typically deployed on private or cellular backhaul with management interfaces kept off the public internet, so only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access to administrative functionality.

Weakness
CWE-603
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.