CVE-2026-77966: Ebyte NA111-M Missing Authorization
The affected Ebyte
product does not provide separation between limited and administrative management functions. A low privileged authenticated attacker could access security sensitive configuration functions and modify settings that affect the confidentiality, integrity, or availability of the device.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated attacker with low-privilege access to the Ebyte NA111-M management interface can exploit it. No user interaction is required, and the vulnerability is reachable over the network.
What could an attacker do after exploiting it?
The attacker could access security-sensitive configuration functions that should be restricted to administrators. They could modify settings affecting the device's confidentiality, integrity, or availability.
Is unauthenticated access enough to exploit the vulnerability?
No. The provided severity vector indicates that low privileges are required, so the attacker must first authenticate with a low-privilege account.