CVE-2026-75813

Summary

Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise of device functionality.

Affected Software

VendorProductVersion RangeStatus
EbyteEbyte NE2-D11 FirmwareFW-9167-0-11affected

Weaknesses

  • CWE-862: CWE-862

Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.

References