Sensitive Configuration Information Exposure in Ebyte Products
CVE-2026-77975

7.1HIGH

Key Information:

Vendor

Ebyte

Vendor
CVE Published:
31 August 2026

What is CVE-2026-77975?

The Ebyte product line has a critical vulnerability where sensitive configuration files, including administrative credentials, are exported without adequate protection. This flaw allows an unauthenticated attacker within the adjacent network to intercept these files and gain unauthorized access to the device and potentially other similarly configured systems. It is essential for Ebyte users to implement additional security measures to safeguard against this threat.

Affected Version(s)

Ebyte NE2-D11 Firmware 9013-2-17

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jithin Nambiar reported this vulnerability to CISA.
.