product exports administrative credentials and other
sensitive configuration information without adequate protection. An
unauthenticated attacker on the adjacent network who can obtain an
exported configuration file could recover valid credentials and use them
to access the device or similarly configured systems.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ebyte
Ebyte ebyte Ne2-d11 Firmware |
|
| Vendors & Products |
Ebyte
Ebyte ebyte Ne2-d11 Firmware |
Mon, 31 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use them to access the device or similarly configured systems. | |
| Title | Ebyte NA111-M Cleartext Storage of Sensitive Information | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-31T15:39:13.452Z
Reserved: 2026-08-21T19:56:57.903Z
Link: CVE-2026-77975
No data.
Status : Deferred
Published: 2026-08-31T16:19:13.190
Modified: 2026-08-31T19:18:40.503
Link: CVE-2026-77975
No data.
OpenCVE Enrichment
Updated: 2026-08-31T16:45:03Z
-
CWE-312
Cleartext Storage of Sensitive Information