VYPR
Vypr IntelligenceAI-generatedAug 28, 2026· 7 CVEs

Cisagov CSAF: Seven Vulnerabilities Disclosed Together Impact Xiiaozet and Ebyte Devices

Seven critical and high-severity vulnerabilities disclosed together impact Cisagov CSAF products, including Xiiaozet and Ebyte devices, enabling unauthorized access and control.

Key findings

  • Seven critical and high-severity vulnerabilities disclosed on August 28, 2026, affect Cisagov CSAF products.
  • Vulnerabilities include missing authentication, command injection, and cleartext transmission of sensitive information.
  • Affected products include Xiiaozet LK100W and Ebyte gateway devices.
  • Exploitation could lead to unauthorized access, command execution, and full device compromise.
  • Users are urged to update firmware to patched versions to mitigate risks.

On August 28, 2026, a batch of seven critical and high-severity vulnerabilities was disclosed across Cisagov's CSAF product line, impacting Xiiaozet LK100W devices and Ebyte gateway products. These vulnerabilities, disclosed on the same day, could allow remote attackers to gain unauthorized access, execute arbitrary commands, and compromise device functionality.

The vulnerabilities are grouped as follows:

Xiiaozet LK100W:

  • **CVE-2026-78239 and CVE-2026-76943** are critical (CVSSv3 9.8) vulnerabilities related to missing authentication for critical functions and authentication bypass, respectively. These flaws could allow remote attackers to enable administrative services or bypass access controls, leading to unauthorized access and command execution.
  • **CVE-2026-78037** is a high-severity (CVSSv3 8.8) OS command injection vulnerability. An authenticated attacker can exploit this through the web-based management interface to execute arbitrary OS commands with elevated privileges.
  • **CVE-2026-75813** is a high-severity (CVSSv3 7.5) vulnerability where certain configuration endpoints lack proper server-side authorization checks, allowing unauthorized users to modify sensitive device settings and potentially leading to full device compromise.

Ebyte Gateway Products (including NA111-M and NE2-D11):

  • **CVE-2026-76179** is a critical (CVSSv3 9.8) vulnerability concerning the improper protection of authentication tokens in the web management interface. Attackers with access to exposed session information could hijack authenticated sessions.
  • **CVE-2026-73809** is a high-severity (CVSSv3 7.5) vulnerability involving the cleartext transmission of sensitive information, such as authentication or session data, over the web management interface due to a lack of transport-layer encryption.
  • **CVE-2026-69658** is a critical (CVSSv3 9.8) vulnerability where MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information and enabling unauthorized device impersonation.

According to CISA advisories, successful exploitation of these vulnerabilities could allow an attacker to take control of the affected devices. Specifically, Xiiaozet LK100W devices with firmware versions prior to 2.1.240 are affected by CVE-2026-78037, CVE-2026-78239, and CVE-2026-76943. Ebyte NA111-M devices with firmware version 9013-2-17 and Ebyte NE2-D11 devices with firmware FW-9167-0-11 are affected by various combinations of the Ebyte-related CVEs.

Users of Cisagov CSAF products, particularly Xiiaozet LK100W and Ebyte gateway devices, are urged to update their firmware to the patched versions as soon as possible to mitigate the risk of device compromise and unauthorized access. The coordinated disclosure of these vulnerabilities highlights the importance of timely patching and security updates for IoT and industrial control systems.

AI-written article. Grounded in 7 CVE records listed below.