Ebyte 网关产品中存在认证令牌保护不当的漏洞。Web 管理界面所使用的认证令牌在客户端会话处理过程中保护不足,这可能使能够访问暴露的会话信息的攻击者获取并复用有效令牌。成功利用该漏洞后,攻击者可冒充已认证用户,从而获得对设备管理功能的未授权访问权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ebyte | Ebyte NE2-D11 Firmware | FW-9167-0-11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ebyte | Ebyte NE2-D11 Firmware | FW-9167-0-11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71187 | 9.8 CRITICAL | Ebyte NE2-D11 Use of Client-Side Authentication |
| CVE-2026-69658 | 9.8 CRITICAL | Ebyte NE2-D11 Cleartext Transmission of Sensitive Information |
| CVE-2026-73125 | 9.8 CRITICAL | Ebyte NE2-D11 Missing Authentication for Critical Function |
| CVE-2026-75814 | 8.8 HIGH | Ebyte NE2-D11 Cross-Site Request Forgery |
| CVE-2026-77977 | 8.1 HIGH | Ebyte NE2-D11 Missing Authentication for Critical Function |
| CVE-2026-75813 | 7.5 HIGH | Ebyte NE2-D11 Missing Authorization |
| CVE-2026-76940 | 7.5 HIGH | Ebyte NE2-D11 Improper Restriction of Excessive Authentication Attempts |
| CVE-2026-76945 | 7.5 HIGH | Ebyte NE2-D11 Use of Client-Side Authentication |
| CVE-2026-73809 | 7.5 HIGH | Ebyte NE2-D11 Cleartext Transmission of Sensitive Information |
| CVE-2026-75548 | 5.4 MEDIUM | Ebyte NE2-D11 Improper Restriction of Rendered UI Layers or Frames |
| CVE-2026-73839 | 4.6 MEDIUM | Ebyte NE2-D11 Insufficiently Protected Credentials |
No comments yet