Multiple Critical Vulnerabilities Discovered in Ebyte NE2-D11 Devices
CISA has issued an advisory detailing several critical vulnerabilities in Ebyte NE2-D11 devices, potentially allowing unauthenticated attackers to gain administrative access and disrupt operations.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory highlighting multiple critical vulnerabilities affecting Ebyte NE2-D11 devices, specifically firmware version FW-9167-0-11. These flaws, if exploited, could grant unauthenticated attackers significant control over the affected industrial control system (ICS) devices, leading to unauthorized administrative access, disclosure of sensitive information, modification of device configurations, session hijacking, and disruption of device operations.
The vulnerabilities span several categories, including missing authentication for critical functions (CVE-2026-73125 and CVE-2026-71187), cleartext transmission of sensitive information (CVE-2026-73809), insufficiently protected credentials (CVE-2026-73839), and use of client-side authentication (CVE-2026-71187). The most severe, CVE-2026-73125 and CVE-2026-71187, carry a CVSS v3.1 base score of 9.8 (Critical), indicating a high potential for exploitation. These flaws allow attackers to bypass authentication mechanisms entirely, leading to full administrative control.
CVE-2026-73809 specifically addresses the insecure transmission of sensitive data over networks. The web management interface fails to adequately protect communications using transport-layer encryption, meaning an attacker with network visibility could intercept authentication credentials or session tokens. This could lead to unauthorized access to the device's management functions.
Furthermore, CVE-2026-73839 points to the exposure of administrative credentials in plaintext within the device's management interface. This increases the risk of credential compromise through various means, including visual observation or network sniffing, undermining the confidentiality of device access.
Ebyte has acknowledged the reported vulnerabilities and indicated that a patch is under development. However, the vendor has not provided a timeline for the patch's release and has reportedly not responded to subsequent requests for coordination with CISA. This lack of timely response and communication leaves users in a precarious position, with no immediate solution to mitigate these critical risks.
Given the widespread deployment of Ebyte devices in critical infrastructure sectors such as critical manufacturing and energy, and their global presence, the impact of these vulnerabilities could be significant. Attackers could leverage these flaws to disrupt essential services, compromise sensitive industrial processes, or gain a foothold for further network intrusion.
CISA strongly encourages users to reach out directly to Ebyte for more information regarding the status and availability of patches. In the interim, organizations using affected Ebyte NE2-D11 devices should consider implementing all available mitigations and enhancing their network monitoring to detect any suspicious activity targeting these devices. The lack of a provided patch, coupled with the critical nature of the vulnerabilities, necessitates a proactive approach to security for affected entities.