top of page
perceptive_background_267k.jpg

The Ebyte device does not adequately verify the origin or authenticity of
requests submitted to the web management interface. An unauthenticated
remote attack…

Published:

28 augustus 2026 om 00:00:00

Alert date:

28 augustus 2026 om 03:09:12

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Critical Infrastructure, Network Infrastructure

CVE-2026-75814 affects Ebyte devices, which fail to adequately verify the origin or authenticity of requests to their web management interface. This cross-site request forgery (CSRF) vulnerability allows an unauthenticated remote attacker to trick an authenticated administrator into visiting a crafted page. Successful exploitation can result in unauthorized configuration changes or disruption of device availability. The vulnerability requires social engineering of an authenticated administrator but does not require the attacker to be authenticated themselves. It has been reported via NVD and is associated with an ICS advisory published by CISA (icsa-26-237-06). Given its impact on device availability and configuration integrity, it poses a significant risk to operational technology environments. The CSAF advisory is available through CISA's GitHub repository.

Technical details

Mitigation steps:

Affected products:

Ebyte device

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page