CVE-2026-77975: Ebyte NA111-M Cleartext Storage of Sensitive Information
The affected Ebyte
product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use them to access the device or similarly configured systems.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker on the adjacent network can exploit the issue if they can obtain an exported configuration file from an affected device.
What can an attacker gain from an exported configuration file?
The file may expose administrative credentials and other sensitive configuration information. Recovered credentials could be used to access the device or similarly configured systems.
Are systems beyond the affected device at risk?
Yes. If the recovered credentials are reused on similarly configured systems, an attacker may be able to access those systems as well.