ZeroHour

CVE-2026-77966

Missing Authorization in Ebyte NA111-M Serial-to-Ethernet Module (CVE-2026-77966)

CVSS 4.0
8.7 high
EPSS
<1%p37
Published
()
Modified
AI analysis

The Ebyte NA111-M does not enforce separation between limited-user and administrative management functions, a missing-authorization issue (CWE-862). An attacker holding valid low-privileged credentials can reach security-sensitive configuration functions over the network, with no user interaction required. By modifying those settings, the attacker can affect the confidentiality, integrity, or availability of the device itself; the CVSS 4.0 scoring indicates no impact on downstream systems. Only deployments of the NA111-M that expose the management interface and have low-privileged accounts are affected. Exploitation has not been observed: there is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days.

What to do: Because no fixed version is specified in the available data, check the CISA ICS-CERT advisory and Ebyte's channels for updated NA111-M firmware and apply it when released. In the interim, restrict access to the device's management interface via network segmentation and allowlisting, and audit or revoke low-privileged accounts that should not be able to change device configuration.

Affected
Ebyte NA111-M
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The affected Ebyte product does not provide separation between limited and administrative management functions. A low privileged authenticated attacker could access security sensitive configuration functions and modify settings that affect the confidentiality, integrity, or availability of the device.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Ebyte NA111-M

CISA reports 13 vulnerabilities, including CVSS 9.8 missing-authentication flaws, in Ebyte NA111-M firmware that allow full device compromise.

CISA published ICS advisory ICSA-26-239-05 for Ebyte NA111-M firmware 9013-2-17, listing 13 vulnerabilities tracked from CVE-2026-73125 through CVE-2026-77977. The issues include missing authentication for critical functions, GET requests with sensitive query strings, cross-site request forgery, improper restriction of excessive authentication attempts, and missing authorization. The vendor-assessed CVSS v3 score is 9.8, and successful exploitation could allow an attacker to fully compromise the device. No remediation details are included in the summary text.