CVE-2026-76945
moderateAuthentication Bypass via Token Replay in Ebyte Devices
The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation (CWE-603), meaning authentication is accepted based on values supplied or controlled by the client rather than verified against an authoritative source. An attacker who can reach the device's authentication mechanism over the network (AV:N, no privileges or user interaction required) can replay a previously captured token or manipulate a presented token to bypass authentication. Successful abuse grants unauthorized access to administrative functionality, with the CVSS base indicating a high impact on confidentiality of the vulnerable system and no integrity or availability impact scored. Any operator of the affected Ebyte device is exposed; the advisory data does not identify the specific model or version range. No public proof-of-concept exists, the issue is not in CISA's KEV, and EPSS assigns a 0.4% (30th percentile) probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Identify which Ebyte device(s) your organization operates and check whether the administrative interface is reachable from untrusted networks; restrict access with firewall ACLs, network segmentation, or a VPN until a vendor fix is available. Monitor the CISA ICS-CERT advisory and Ebyte firmware release channels for the affected model and a patched version, then update promptly — no fixed version numbers are available in the current data. In the interim, consider rotating credentials or sessions and reviewing device logs for unexpected administrative logins.
| Ebyte Affected Ebyte device (specific model not identified in the provided advisory data; assigned by CISA ICS-CERT, indicatin | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access to administrative functionality.
- Weakness
- CWE-603
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.