Web Management Interface Vulnerability in Ebyte Devices
CVE-2026-75548
5.3MEDIUM
What is CVE-2026-75548?
The web management interface of Ebyte devices is susceptible to a vulnerability where it does not implement adequate restrictions against being framed within external websites. This flaw allows an unauthenticated remote attacker to construct a malicious webpage that, when visited by an authenticated administrator, could result in unauthorized configuration alterations or other disruptive actions.
Affected Version(s)
Ebyte NE2-D11 Firmware FW-9167-0-11
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jithin Nambiar reported this vulnerability to CISA.
