VORANT. Threat Intelligence Sign in Get the full feed

Ebyte NE2-D11 gateway riddled with auth flaws

routine vulnerability education

CISA advises Ebyte NE2-D11 gateways contain 12 vulnerabilities allowing unauthenticated attackers to bypass authentication, hijack sessions, and disrupt device operation.

CISA published an ICS advisory detailing 12 vulnerabilities affecting the Ebyte NE2-D11 gateway (firmware FW-9167-0-11), a device deployed worldwide in Critical Manufacturing and Energy sectors and manufactured by a China-headquartered vendor. The flaws span missing authentication for critical functions, cleartext transmission of credentials and MQTT traffic, plaintext-exposed admin credentials, client-side authentication logic that can be reproduced by attackers, improperly protected/replayable session tokens, CSRF, clickjacking (missing frame protections), missing server-side authorization on configuration endpoints, and lack of rate limiting/lockout for authentication attempts.

Combined, these issues could let an unauthenticated remote attacker gain full administrative access to the device, intercept or replay authentication tokens, alter configuration, disclose sensitive information, and disrupt availability — collectively representing a near-complete compromise of device confidentiality, integrity, and availability with low attacker sophistication required (many issues need only network access or a crafted webpage/CSRF lure).

Ebyte acknowledged the report and stated a patch was in development but has since stopped responding to CISA's coordination requests; no patch availability has been confirmed. There is no known public exploitation at this time. CISA recommends standard ICS hardening: isolate control system devices from the internet and business networks, place them behind firewalls, use VPNs for any necessary remote access, and apply defense-in-depth and anti-phishing practices given the CSRF/clickjacking vectors.

Mentioned in this report

Vulnerabilities CVE-2026-69658CVE-2026-71187CVE-2026-73125CVE-2026-73809CVE-2026-73839CVE-2026-75548CVE-2026-75813CVE-2026-75814CVE-2026-76179CVE-2026-76940CVE-2026-76945

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free