VYPR

NE2-D11

by EBYTE

CVEs (11)

  • CVE-2026-71187criAug 25, 2026
    risk 0.64cvss 9.8epss

    Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.

  • CVE-2026-69658criAug 25, 2026
    risk 0.64cvss 9.8epss

    MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.

  • CVE-2026-73125criAug 25, 2026
    risk 0.64cvss 9.8epss

    Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.

  • CVE-2026-76179criAug 25, 2026
    risk 0.64cvss 9.8epss

    An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed…

  • CVE-2026-75814higAug 25, 2026
    risk 0.57cvss 8.8epss

    Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, causing unauthorized configuration changes or a…

  • CVE-2026-75813higAug 25, 2026
    risk 0.49cvss 7.5epss

    Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise of device functionality.

  • CVE-2026-73809higAug 25, 2026
    risk 0.49cvss 7.5epss

    A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could…

  • CVE-2026-76940higAug 25, 2026
    risk 0.49cvss 7.5epss

    The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated authentication attacks against deployments that rely on password based authentication.

  • CVE-2026-76945higAug 25, 2026
    risk 0.49cvss 7.5epss

    The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access to administrative functionality.

  • CVE-2026-75548medAug 25, 2026
    risk 0.35cvss 5.4epss

    The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator into initiating unintended configuration…

  • CVE-2026-73839medAug 25, 2026
    risk 0.30cvss 4.6epss

    Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk of credential compromise through visual or remote observation. This undermines the confidentiality of device access.