


Perceptive Security
SOC/SIEM Consultancy

A cleartext transmission of sensitive information vulnerability exists
in certain Ebyte gateway products. The web management interface does not
adequately pro…
Published:
28 August 2026 at 00:00:00
Alert date:
28 August 2026 at 03:09:12
Source:
nvd.nist.gov
Network Infrastructure, Critical Infrastructure, Mobile & IoT
A cleartext transmission of sensitive information vulnerability has been identified in certain Ebyte gateway products. The web management interface lacks adequate transport-layer encryption, exposing sensitive communications to interception. An attacker with access to network traffic can intercept authentication credentials or session tokens exchanged between users and the affected device. Successful exploitation could lead to unauthorized access to device management functionality and disclosure of sensitive information. The vulnerability is tracked as CVE-2026-73809 and has been reported via NVD and CISA ICS advisory ICSA-26-237-06. It affects OT/ICS gateway devices, making it particularly relevant to critical infrastructure environments. Mitigation likely involves enabling TLS/HTTPS on the web management interface or applying vendor-supplied patches.
Technical details
Mitigation steps:
Affected products:
Ebyte Gateway
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-73809
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
