Administrative Credentials Exposure in Ebyte Device Management Interface
CVE-2026-73839
5.1MEDIUM
What is CVE-2026-73839?
The Ebyte device management interface exposes administrative credentials in plaintext, which can lead to unauthorized access. This vulnerability increases the potential for credential compromise via both visual and remote observation, jeopardizing the confidentiality of device access and management. Users must take precautions to secure their device interfaces to prevent unauthorized access.
Affected Version(s)
Ebyte NE2-D11 Firmware FW-9167-0-11
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jithin Nambiar reported this vulnerability to CISA.
