Administrative Credentials Exposure in Ebyte Device Management Interface
CVE-2026-73839

5.1MEDIUM

Key Information:

Vendor

Ebyte

Vendor
CVE Published:
27 August 2026

What is CVE-2026-73839?

The Ebyte device management interface exposes administrative credentials in plaintext, which can lead to unauthorized access. This vulnerability increases the potential for credential compromise via both visual and remote observation, jeopardizing the confidentiality of device access and management. Users must take precautions to secure their device interfaces to prevent unauthorized access.

Affected Version(s)

Ebyte NE2-D11 Firmware FW-9167-0-11

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jithin Nambiar reported this vulnerability to CISA.
.