CVE-2026-73809 HIGH

CVE-2026-73809: Ebyte NE2-D11 Cleartext Transmission of Sensitive Information

Vendor Ebyte
Product Ebyte NE2-D11 Firmware
Weakness CWE-319 · Cleartext transmission
Published August 27, 2026
Last update August 28, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful exploitation could result in disclosure of sensitive information and unauthorized access to device management functionality.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 28, 2026 Record updated