CVE-2026-75814: Ebyte NE2-D11 Cross-Site Request Forgery
Published Aug 27, 2026
·Updated
The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, causing unauthorized configuration changes or a disruption of device availability.
Affected Software
1 affected component
Ebyte NE2-D11
Event History
Aug 27, 2026
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What conditions are required for exploitation?
An attacker can be remote and unauthenticated, but must persuade an authenticated administrator to visit a crafted page while the administrator can access the device's web management interface.
2
What could an attacker accomplish through exploitation?
Successful exploitation can cause unauthorized configuration changes or disrupt the availability of the Ebyte NE2-D11 device.