{"id":"CVE-2026-73809","title":"Ebyte NA111-M Cleartext Transmission of Sensitive Information","summary":"A cleartext transmission of sensitive information vulnerability exists \nin certain Ebyte gateway products. The web management interface does not\n adequately protect sensitive communications using transport-layer \nencryption. An attacker …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cvssSource":"cna","cwe":["CWE-319"],"vendor":"Ebyte","product":"Ebyte NA111-M Firmware","affected":["na111-m_firmware 9013-2-17"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-08-28T13:56:04.522476Z"},"published":"2026-08-27","updated":"2026-10-05","sourceUpdated":"2026-10-05T19:22:57.999Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-73809","references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json"}],"tags":["cve.org"],"epss":0.00223,"epssPercentile":0.11759,"ingestedAt":"2026-10-05T20:32:56.662Z","slug":"CVE-2026-73809","body":"## Overview\n\nA cleartext transmission of sensitive information vulnerability exists \nin certain Ebyte gateway products. The web management interface does not\n adequately protect sensitive communications using transport-layer \nencryption. An attacker with access to network traffic could intercept \nauthentication or session-related information transmitted between a user\n and the affected device. Successful exploitation could result in \ndisclosure of sensitive information and unauthorized access to device \nmanagement functionality.\n\n## Affected\n\n- `na111-m_firmware 9013-2-17`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n### Workarounds\n\nEbyte acknowledged receipt of the reported vulnerabilities and indicated\n that a patch was under development. However, the vendor has not \nresponded to subsequent requests for coordination, and CISA has not been\n informed of the status or availability of the patch. Users are \nencouraged to reach out to Ebyte for more information.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}