# Ebyte NE2-D11 gateway riddled with auth flaws

Published: 2026-08-25 · Severity: routine · Sectors: education
Canonical: https://vorant.io/reports/bd02f458-7c13-52be-977a-16dc943a103f/ebyte-ne2-d11-gateway-riddled-with-auth-flaws

> CISA advises Ebyte NE2-D11 gateways contain 12 vulnerabilities allowing unauthenticated attackers to bypass authentication, hijack sessions, and disrupt device operation.

CISA published an ICS advisory detailing 12 vulnerabilities affecting the Ebyte NE2-D11 gateway (firmware FW-9167-0-11), a device deployed worldwide in Critical Manufacturing and Energy sectors and manufactured by a China-headquartered vendor. The flaws span missing authentication for critical functions, cleartext transmission of credentials and MQTT traffic, plaintext-exposed admin credentials, client-side authentication logic that can be reproduced by attackers, improperly protected/replayable session tokens, CSRF, clickjacking (missing frame protections), missing server-side authorization on configuration endpoints, and lack of rate limiting/lockout for authentication attempts.

Combined, these issues could let an unauthenticated remote attacker gain full administrative access to the device, intercept or replay authentication tokens, alter configuration, disclose sensitive information, and disrupt availability — collectively representing a near-complete compromise of device confidentiality, integrity, and availability with low attacker sophistication required (many issues need only network access or a crafted webpage/CSRF lure).

Ebyte acknowledged the report and stated a patch was in development but has since stopped responding to CISA's coordination requests; no patch availability has been confirmed. There is no known public exploitation at this time. CISA recommends standard ICS hardening: isolate control system devices from the internet and business networks, place them behind firewalls, use VPNs for any necessary remote access, and apply defense-in-depth and anti-phishing practices given the CSRF/clickjacking vectors.

## Mentioned in this report

- Vulnerabilities: CVE-2026-69658, CVE-2026-71187, CVE-2026-73125, CVE-2026-73809, CVE-2026-73839, CVE-2026-75548, CVE-2026-75813, CVE-2026-75814, CVE-2026-76179, CVE-2026-76940, CVE-2026-76945

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/bd02f458-7c13-52be-977a-16dc943a103f/ebyte-ne2-d11-gateway-riddled-with-auth-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
