AI analysis
The Ebyte NA111-M gateway's vendor configuration utility performs disruptive administrative actions without requiring authentication whenever the device is still using its default credentials. An unauthenticated attacker with access to the adjacent network (e.g., the same LAN or industrial network segment) can trigger a device reboot or a factory reset, wiping the configuration and causing loss of service availability. There is no confidentiality impact, but integrity and availability impacts are rated high under CVSS 4.0 (7.2, High), and the issue is tracked as CWE-306 (Missing Authentication for Critical Function). Organizations operating NA111-M gateways that have not changed the factory default credentials are affected. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.
What to do: Change the default credentials on affected NA111-M gateways so the configuration utility requires authentication, and restrict access to the management interface to trusted network segments. Check gateways for unexplained reboots or unexpected factory-default configurations, and monitor Ebyte's advisories for firmware or utility updates addressing this issue.
Affected
| Ebyte NA111-M gateway (vendor configuration utility) | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on the adjacent network could reboot the device or restore factory settings, resulting in a loss of configuration and service availability.