CVE-2026-69658: Ebyte NE2-D11 Cleartext Transmission of Sensitive Information
Published Aug 27, 2026
·Updated
MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.
Affected Software
1 affected component
Ebyte NE2-D11
Event History
Aug 27, 2026
CVE Published
via MITRE·09:37 PM
Data Sourced
via MITRE·09:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A network-level attacker who can observe traffic between the device and its MQTT infrastructure can obtain cleartext MQTT credentials and control traffic. No authentication or user interaction is required according to the supplied vector.
2
What could an attacker do with exposed MQTT credentials?
The exposed credentials may allow unauthorized device impersonation and disruption of messaging functions. The issue also exposes sensitive information carried in MQTT control traffic.