Ebyte NA111-M: Three Critical Vulnerabilities Disclosed Together by CISA
CISA disclosed three vulnerabilities in Ebyte NA111-M devices on August 31, 2026, ranging from Medium to Critical, with potential for full device compromise.

Key findings
- Three vulnerabilities in Ebyte NA111-M disclosed on August 31, 2026, with severity ranging from Medium to Critical.
- CVE-2026-76133 (Critical) involves a deprecated hashing algorithm weakening authentication.
- CVE-2026-77966 (High) allows privilege escalation due to a lack of management function separation.
- CVE-2026-77975 (Medium) exposes administrative credentials via exported configuration files.
- Successful exploitation could lead to full device compromise, according to CISA.
On August 31, 2026, CISA issued an advisory detailing three vulnerabilities in Ebyte products, specifically the NA111-M device. These vulnerabilities, disclosed together, pose significant risks ranging from medium to critical, with the potential for full device compromise. The advisory highlights issues related to authentication, authorization, and information exposure, underscoring the need for immediate attention from users of the affected Ebyte equipment.
Two of the vulnerabilities, CVE-2026-77966 (High, CVSSv3 8.8) and CVE-2026-76133 (Critical, CVSSv3 9.8), stem from inadequate separation of management functions and the use of deprecated hashing algorithms in authentication, respectively. CVE-2026-77966 allows a low-privileged authenticated attacker to modify security-sensitive settings, impacting the device's confidentiality, integrity, and availability. CVE-2026-76133, on the other hand, could facilitate unauthorized access if an attacker can manipulate or predict the authentication exchange due to the weak hashing algorithm.
The third vulnerability, CVE-2026-77975 (Medium, CVSSv3 6.5), involves the improper protection of exported configuration files, which contain administrative credentials and sensitive information. An unauthenticated attacker on the adjacent network could potentially obtain an exported configuration file and recover valid credentials, leading to unauthorized access.
The CISA advisory (ICSA-26-239-05) indicates that the NA111-M Firmware version 9013-2-17 is affected by these and other vulnerabilities. Successful exploitation of these flaws could allow an attacker to fully compromise the device. The advisory lists a broad range of vulnerabilities affecting this firmware version, including missing authentication for critical functions, improper restriction of excessive authentication attempts, and cleartext transmission of sensitive information, among others.
Users of Ebyte NA111-M devices are urged to consult the CISA advisory and take necessary steps to mitigate these risks. The coordinated disclosure of these vulnerabilities emphasizes a critical security posture for the Ebyte NA111-M, requiring prompt action to secure affected systems and prevent potential exploitation. The range of vulnerabilities points to systemic issues in the product's security architecture that need to be addressed by the vendor.