Missing Authorization in Ebyte NA111-M Serial-to-Ethernet Module (CVE-2026-77966)
AI analysis
The Ebyte NA111-M does not enforce separation between limited-user and administrative management functions, a missing-authorization issue (CWE-862). An attacker holding valid low-privileged credentials can reach security-sensitive configuration functions over the network, with no user interaction required. By modifying those settings, the attacker can affect the confidentiality, integrity, or availability of the device itself; the CVSS 4.0 scoring indicates no impact on downstream systems. Only deployments of the NA111-M that expose the management interface and have low-privileged accounts are affected. Exploitation has not been observed: there is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days.
What to do: Because no fixed version is specified in the available data, check the CISA ICS-CERT advisory and Ebyte's channels for updated NA111-M firmware and apply it when released. In the interim, restrict access to the device's management interface via network segmentation and allowlisting, and audit or revoke low-privileged accounts that should not be able to change device configuration.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The affected Ebyte product does not provide separation between limited and administrative management functions. A low privileged authenticated attacker could access security sensitive configuration functions and modify settings that affect the confidentiality, integrity, or availability of the device.