CVE-2026-73839 MEDIUM

CVE-2026-73839: Ebyte NE2-D11 Insufficiently Protected Credentials

Vendor Ebyte
Product Ebyte NE2-D11 Firmware
Weakness CWE-522 · Insufficiently protected credentials
Published August 27, 2026
Last update August 28, 2026

CVSS base score

4.6/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk of credential compromise through visual or remote observation. This undermines the confidentiality of device access.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 28, 2026 Record updated