亿佰特(Ebyte)网关产品的厂商配置工具在默认凭据仍保留在配置中时,未要求身份验证即允许执行某些具有干扰性的管理操作。同一相邻网络中的未认证攻击者可以重启设备或恢复出厂设置,从而导致配置丢失和服务可用性受损。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ebyte | Ebyte NE2-D11 Firmware | FW-9167-0-11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ebyte | Ebyte NE2-D11 Firmware | FW-9167-0-11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71187 | 9.8 CRITICAL | Ebyte NE2-D11 Use of Client-Side Authentication |
| CVE-2026-69658 | 9.8 CRITICAL | Ebyte NE2-D11 Cleartext Transmission of Sensitive Information |
| CVE-2026-76179 | 9.8 CRITICAL | Ebyte NE2-D11 Use of GET Request Method With Sensitive Query Strings |
| CVE-2026-73125 | 9.8 CRITICAL | Ebyte NE2-D11 Missing Authentication for Critical Function |
| CVE-2026-75814 | 8.8 HIGH | Ebyte NE2-D11 Cross-Site Request Forgery |
| CVE-2026-75813 | 7.5 HIGH | Ebyte NE2-D11 Missing Authorization |
| CVE-2026-76940 | 7.5 HIGH | Ebyte NE2-D11 Improper Restriction of Excessive Authentication Attempts |
| CVE-2026-76945 | 7.5 HIGH | Ebyte NE2-D11 Use of Client-Side Authentication |
| CVE-2026-73809 | 7.5 HIGH | Ebyte NE2-D11 Cleartext Transmission of Sensitive Information |
| CVE-2026-75548 | 5.4 MEDIUM | Ebyte NE2-D11 Improper Restriction of Rendered UI Layers or Frames |
| CVE-2026-73839 | 4.6 MEDIUM | Ebyte NE2-D11 Insufficiently Protected Credentials |
No comments yet