Unauthorized Access in Ebyte Vendor Configuration Utility
CVE-2026-73819

9.3CRITICAL

Key Information:

Vendor

Ebyte

Vendor
CVE Published:
31 August 2026

What is CVE-2026-73819?

The Ebyte Vendor Configuration Utility has a significant access control issue that allows unauthorized users to access administrative functions without proper identity verification under specific credential conditions. This vulnerability could enable an unauthenticated attacker on the adjacent network to alter critical device settings or modify access credentials, severely impacting the ability of legitimate administrators to manage the device effectively. Ensuring robust access controls is essential to mitigate this risk.

Affected Version(s)

Ebyte NA111-M Firmware 9013-2-17

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jithin Nambiar reported this vulnerability to CISA.
.