Unauthorized Access in Ebyte Vendor Configuration Utility
CVE-2026-73819
9.3CRITICAL
What is CVE-2026-73819?
The Ebyte Vendor Configuration Utility has a significant access control issue that allows unauthorized users to access administrative functions without proper identity verification under specific credential conditions. This vulnerability could enable an unauthenticated attacker on the adjacent network to alter critical device settings or modify access credentials, severely impacting the ability of legitimate administrators to manage the device effectively. Ensuring robust access controls is essential to mitigate this risk.
Affected Version(s)
Ebyte NA111-M Firmware 9013-2-17
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jithin Nambiar reported this vulnerability to CISA.
