CVE-2026-77977: Ebyte NE2-D11 Missing Authentication for Critical Function
Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on the adjacent network could reboot the device or restore factory settings, resulting in a loss of configuration and service availability.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Ebyte NE2-D11 devices are exposed when they retain default credentials and are reachable by an attacker on the adjacent network.
What can an unauthenticated attacker do?
An attacker can use the vendor configuration utility to reboot the device or restore it to factory settings. This can erase configuration and disrupt service availability.
Does exploitation require valid credentials or user interaction?
No. The vulnerability is exploitable without authentication or user interaction, but the attacker must have adjacent-network access.