VYPR

Ebyte device web management interface

by EBYTE

CVEs (2)

  • CVE-2026-73125CriAug 28, 2026
    risk 0.64cvss 9.8epss 0.01

    Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.

  • CVE-2026-75548MedAug 28, 2026
    risk 0.35cvss 5.4epss 0.00

    The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator into initiating unintended configuration …