news.mlab.sh
Back to the feed
vulnerability

Ebyte NA111-M

High
Summary

A series of vulnerabilities have been identified in Ebyte NA111-M devices, primarily related to authentication and configuration management. These flaws allow unauthenticated attackers to access sensitive information, modify device settings, and potentially disrupt device availability. Despite CISA reporting these issues, Ebyte has not responded to coordination requests for a patch, leaving users vulnerable.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory regarding critical vulnerabilities in the Ebyte NA111-M device. These vulnerabilities stem from a lack of consistent authentication enforcement and inadequate protection of sensitive communications. The affected devices, manufactured by Ebyte and headquartered in China, are used in various Information Technology infrastructure.

Specifically, the device’s web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt device availability. The vulnerabilities include a lack of proper rate limiting, weak hashing algorithms in authentication operations, and the ability to export administrative credentials without adequate protection.

Ebyte has acknowledged receipt of the reported vulnerabilities but has not responded to subsequent requests for coordination regarding a patch. This lack of vendor responsiveness is a significant concern, as users are currently exposed to these risks. The vulnerabilities are detailed in the following list:

  • NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977)

CISA recommends users take defensive measures to minimize the risk of exploitation, including minimizing network exposure for control system devices and ensuring default credentials are changed immediately.

Read the full article at CISA Advisories