{"id":"CVE-2026-75548","title":"Ebyte NA111-M Improper Restriction of Rendered UI Layers or Frames","summary":"The affected Ebyte device web management interface does not restrict the\n interface from being rendered within an external frame. An \nunauthenticated remote attacker could use a crafted webpage to mislead \nan authenticated administrator …","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","cvssSource":"cna","cwe":["CWE-1021"],"vendor":"Ebyte","product":"Ebyte NA111-M Firmware","affected":["na111-m_firmware 9013-2-17"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-28T13:49:33.347547Z"},"published":"2026-08-27","updated":"2026-10-05","sourceUpdated":"2026-10-05T19:24:37.557Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-75548","references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json"}],"tags":["cve.org"],"epss":0.00291,"epssPercentile":0.19677,"ingestedAt":"2026-10-05T20:32:56.661Z","slug":"CVE-2026-75548","body":"## Overview\n\nThe affected Ebyte device web management interface does not restrict the\n interface from being rendered within an external frame. An \nunauthenticated remote attacker could use a crafted webpage to mislead \nan authenticated administrator into initiating unintended configuration \nchanges or disruptive actions.\n\n## Affected\n\n- `na111-m_firmware 9013-2-17`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n### Workarounds\n\nEbyte acknowledged receipt of the reported vulnerabilities and indicated\n that a patch was under development. However, the vendor has not \nresponded to subsequent requests for coordination, and CISA has not been\n informed of the status or availability of the patch. Users are \nencouraged to reach out to Ebyte for more information.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}