CISA Warns of Critical Vulnerabilities in Ebyte NA111-M Firmware
CISA has issued an advisory detailing multiple critical vulnerabilities in Ebyte NA111-M firmware version 9013-2-17, which could allow unauthenticated attackers to fully compromise the device.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a critical advisory concerning numerous vulnerabilities affecting the Ebyte NA111-M industrial control system firmware. The affected version, 9013-2-17, contains a suite of security flaws that, if exploited, could grant unauthenticated attackers complete control over the device.
These vulnerabilities span several categories, including missing authentication for critical functions, improper session handling, cross-site request forgery (CSRF), and insufficient protection of authentication tokens. Specifically, CVE-2026-73125 highlights a failure to consistently enforce authentication, allowing remote attackers to access sensitive configurations, alter settings, or disrupt device availability. Another critical flaw, CVE-2026-76179, involves insufficiently protected authentication tokens, enabling attackers to impersonate authenticated users by obtaining and reusing valid session tokens.
Further compounding the risk, CVE-2026-75814 details a Cross-Site Request Forgery (CSRF) vulnerability, where attackers can trick authenticated administrators into performing unauthorized actions by visiting malicious web pages. The advisory also points to improper restriction of excessive authentication attempts (CVE-2026-76940), meaning brute-force attacks against password-based authentication could be more easily successful. Additionally, flaws like improper restriction of rendered UI layers or frames and weak authentication mechanisms are present.
The potential impact of these vulnerabilities is severe, with CVSS scores reaching as high as 9.8 (Critical). Successful exploitation could lead to a full device compromise, impacting the confidentiality, integrity, and availability of the industrial systems these devices manage. The advisory lists thirteen specific CVEs associated with these issues, underscoring the breadth of the security weaknesses.
Ebyte, the vendor, has acknowledged the reported vulnerabilities and indicated that a patch is under development. However, the company has not responded to subsequent requests for coordination, and CISA has not been informed of the patch's status or availability. This lack of vendor response leaves users in a precarious position, with no clear timeline for remediation.
CISA is urging users to reach out directly to Ebyte for more information regarding the patch. In the interim, organizations using the affected Ebyte NA111-M firmware should consider implementing all available mitigation strategies and closely monitor for any further communication from the vendor or security advisories. The widespread deployment of Ebyte devices, with headquarters in China and reported worldwide usage, amplifies the potential scope of this threat.
This advisory serves as a critical reminder of the ongoing security challenges within the Industrial Internet of Things (IIoT) and operational technology (OT) sectors. The interconnected nature of these systems means that vulnerabilities in even seemingly minor components can have cascading effects on critical infrastructure. The lack of timely vendor response further exacerbates the risk, highlighting the importance of proactive security measures and robust incident response planning for organizations relying on such equipment.