CVE-2026-73819: Ebyte NA111-M Weak Authentication
The affected Ebyte
product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing legitimate administrators from managing the device.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to exploitation?
Devices reachable by an attacker on an adjacent network are exposed when the vendor configuration utility is accessible and the relevant credential conditions are present.
What does an attacker need to exploit this issue?
An attacker does not need authentication or user interaction, but must be on an adjacent network and encounter the credential conditions that allow the utility to grant administrative access without verifying identity.