{"id":"CVE-2026-75814","title":"Ebyte NA111-M Cross-Site Request Forgery","summary":"The Ebyte device does not adequately verify the origin or authenticity of \nrequests submitted to the web management interface. An unauthenticated \nremote attacker could persuade an authenticated administrator to visit a\n crafted page, ca…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-352"],"vendor":"Ebyte","product":"Ebyte NA111-M Firmware","affected":["na111-m_firmware 9013-2-17"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-08-28T13:49:45.761914Z"},"published":"2026-08-27","updated":"2026-10-05","sourceUpdated":"2026-10-05T19:21:33.592Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-75814","references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json"}],"tags":["cve.org"],"epss":0.00247,"epssPercentile":0.1456,"ingestedAt":"2026-10-05T20:32:56.662Z","slug":"CVE-2026-75814","body":"## Overview\n\nThe Ebyte device does not adequately verify the origin or authenticity of \nrequests submitted to the web management interface. An unauthenticated \nremote attacker could persuade an authenticated administrator to visit a\n crafted page, causing unauthorized configuration changes or a \ndisruption of device availability.\n\n## Affected\n\n- `na111-m_firmware 9013-2-17`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n### Workarounds\n\nEbyte acknowledged receipt of the reported vulnerabilities and indicated\n that a patch was under development. However, the vendor has not \nresponded to subsequent requests for coordination, and CISA has not been\n informed of the status or availability of the patch. Users are \nencouraged to reach out to Ebyte for more information.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}