CVE-2026-76179 CRITICAL

CVE-2026-76179: Ebyte NE2-D11 Use of GET Request Method With Sensitive Query Strings

Vendor Ebyte
Product Ebyte NE2-D11 Firmware
Weakness CWE-598
Published August 27, 2026
Last update August 28, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 28, 2026 Record updated