


Perceptive Security
SOC/SIEM Consultancy

Ebyte device web management interface does not consistently enforce
authentication before granting access to administrative functionality.
An unauthenticated …
Published:
28 augustus 2026 om 00:00:00
Alert date:
28 augustus 2026 om 03:09:12
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Critical Infrastructure, Identity & Access
CVE-2026-73125 describes a critical authentication bypass vulnerability in the Ebyte device web management interface. The interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker can exploit this flaw to access sensitive configuration information, modify device settings, or disrupt device availability. The vulnerability is categorized as missing authentication for critical function. It affects OT/IoT network devices manufactured by Ebyte. CISA has published an ICS advisory (ICSA-26-237-06) addressing this issue. The flaw poses significant risk to industrial and operational technology environments where Ebyte devices are deployed. No authentication or special privileges are required to exploit this vulnerability remotely.
Technical details
Mitigation steps:
Affected products:
Ebyte device web management interface
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-73125
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
