


Perceptive Security
SOC/SIEM Consultancy

Ebyte NA111-M
Published:
27 augustus 2026 om 14:00:00
Alert date:
27 augustus 2026 om 19:04:22
Source:
cisa.gov
Critical Infrastructure, Mobile & IoT, Network Infrastructure, Identity & Access
CISA issued an ICS advisory (ICSA-26-239-05) for Ebyte NA111-M Firmware 9013-2-17, disclosing 13 vulnerabilities with a maximum CVSS v3 score of 9.8 (Critical). Successful exploitation could allow an attacker to fully compromise the device. Vulnerabilities include Missing Authentication for Critical Functions, CSRF, Use of Client-Side Authentication, Cleartext Transmission of Sensitive Information (HTTP and MQTT), Weak Authentication, Missing Authorization, Broken Cryptographic Algorithms, and Cleartext Storage of Sensitive Information. The device is deployed worldwide in the Information Technology critical infrastructure sector by China-based vendor Ebyte. Ebyte acknowledged the vulnerabilities and indicated a patch was under development but has not responded to subsequent coordination requests. No patch is currently available; CISA recommends network isolation, firewall segmentation, and VPN use as mitigations. The vulnerabilities were reported by Jithin Nambiar J.
Technical details
Mitigation steps:
Affected products:
Ebyte NA111-M Firmware 9013-2-17
Related links:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-05.json
https://www.cve.org/CVERecord?id=CVE-2026-73125
https://www.cve.org/CVERecord?id=CVE-2026-76179
https://www.cve.org/CVERecord?id=CVE-2026-75814
https://www.cve.org/CVERecord?id=CVE-2026-76940
https://www.cve.org/CVERecord?id=CVE-2026-77966
https://www.cve.org/CVERecord?id=CVE-2026-73809
https://www.cve.org/CVERecord?id=CVE-2026-71187
https://www.cve.org/CVERecord?id=CVE-2026-75548
https://www.cve.org/CVERecord?id=CVE-2026-69658
https://www.cve.org/CVERecord?id=CVE-2026-76133
https://www.cve.org/CVERecord?id=CVE-2026-73819
https://www.cve.org/CVERecord?id=CVE-2026-77975
https://www.cve.org/CVERecord?id=CVE-2026-77977
https://cwe.mitre.org/data/definitions/306.html
https://cwe.mitre.org/data/definitions/598.html
https://cwe.mitre.org/data/definitions/352.html
https://cwe.mitre.org/data/definitions/307.html
https://cwe.mitre.org/data/definitions/862.html
https://cwe.mitre.org/data/definitions/319.html
https://cwe.mitre.org/data/definitions/603.html
https://cwe.mitre.org/data/definitions/1021.html
https://cwe.mitre.org/data/definitions/327.html
https://cwe.mitre.org/data/definitions/1390.html
https://cwe.mitre.org/data/definitions/312.html
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
https://www.cisa.gov/notification
https://www.cisa.gov/privacy-policy
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
