CVE-2026-76940

Summary

The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated authentication attacks against deployments that rely on password based authentication.

Affected Software

VendorProductVersion RangeStatus
EbyteEbyte NE2-D11 FirmwareFW-9167-0-11affected

Weaknesses

  • CWE-307: CWE-307

Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.

References