top of page
perceptive_background_267k.jpg

Ebyte device web management interface does not consistently enforce
authentication before granting access to administrative functionality.
An unauthenticated …

Published:

28 augustus 2026 om 00:00:00

Alert date:

28 augustus 2026 om 03:09:12

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure, Critical Infrastructure, Identity & Access

CVE-2026-73125 describes a critical authentication bypass vulnerability in the Ebyte device web management interface. The interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker can exploit this flaw to access sensitive configuration information, modify device settings, or disrupt device availability. The vulnerability is categorized as missing authentication for critical function. It affects OT/IoT network devices manufactured by Ebyte. CISA has published an ICS advisory (ICSA-26-237-06) addressing this issue. The flaw poses significant risk to industrial and operational technology environments where Ebyte devices are deployed. No authentication or special privileges are required to exploit this vulnerability remotely.

Technical details

Mitigation steps:

Affected products:

Ebyte device web management interface

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page