ZeroHour

CVE-2026-77975

Cleartext Credential Storage in Ebyte NA111-M Configuration Export

CVSS 4.0
7.1 high
EPSS
<1%p8
Published
()
Modified
AI analysis

The affected Ebyte device, identified in related reporting as the NA111-M, exports administrative credentials and other sensitive configuration information without adequate protection (cleartext storage of sensitive information, CWE-312). An unauthenticated attacker positioned on the adjacent network who can obtain an exported configuration file can recover the stored credentials and use them to authenticate to the device. Because credentials may be reused, the attacker could also gain access to similarly configured systems in the deployment. Any site operating the affected Ebyte product, particularly industrial or IoT deployments where configuration files are exchanged or archived, is potentially affected. No public proof-of-concept, CISA KEV listing, or known exploitation exists; EPSS estimates only a 0.2% chance of exploitation in the next 30 days.

What to do: Restrict access to exported configuration files, rotate administrative credentials on any device whose configuration export has been shared or stored, and segment networks to limit adjacent-network access to device management interfaces. Monitor CISA ICS-CERT and vendor advisories for confirmed affected firmware ranges and apply the fixed firmware as soon as it is published.

Affected
Ebyte NA111-M
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use them to access the device or similarly configured systems.

Weakness
CWE-312
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Ebyte NA111-M

CISA reports 13 vulnerabilities, including CVSS 9.8 missing-authentication flaws, in Ebyte NA111-M firmware that allow full device compromise.

CISA published ICS advisory ICSA-26-239-05 for Ebyte NA111-M firmware 9013-2-17, listing 13 vulnerabilities tracked from CVE-2026-73125 through CVE-2026-77977. The issues include missing authentication for critical functions, GET requests with sensitive query strings, cross-site request forgery, improper restriction of excessive authentication attempts, and missing authorization. The vendor-assessed CVSS v3 score is 9.8, and successful exploitation could allow an attacker to fully compromise the device. No remediation details are included in the summary text.