


Perceptive Security
SOC/SIEM Consultancy

The Ebyte device does not adequately verify the origin or authenticity of
requests submitted to the web management interface. An unauthenticated
remote attack…
Published:
28 augustus 2026 om 00:00:00
Alert date:
28 augustus 2026 om 03:09:12
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure, Network Infrastructure
CVE-2026-75814 affects Ebyte devices, which fail to adequately verify the origin or authenticity of requests to their web management interface. This cross-site request forgery (CSRF) vulnerability allows an unauthenticated remote attacker to trick an authenticated administrator into visiting a crafted page. Successful exploitation can result in unauthorized configuration changes or disruption of device availability. The vulnerability requires social engineering of an authenticated administrator but does not require the attacker to be authenticated themselves. It has been reported via NVD and is associated with an ICS advisory published by CISA (icsa-26-237-06). Given its impact on device availability and configuration integrity, it poses a significant risk to operational technology environments. The CSAF advisory is available through CISA's GitHub repository.
Technical details
Mitigation steps:
Affected products:
Ebyte device
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-75814
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
