CVE-2026-77975 MEDIUM

CVE-2026-77975: Ebyte NA111-M Cleartext Storage of Sensitive Information

Vendor Ebyte
Product Ebyte NE2-D11 Firmware
Weakness CWE-312 · Cleartext storage
Published August 31, 2026
Last update October 5, 2026

CVSS base score

6.5/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use them to access the device or similarly configured systems.

Key dates

02Disclosure timeline

August 31, 2026 CVE published
October 5, 2026 Record updated