{"id":"CVE-2026-76179","title":"Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings","summary":"An improper protection of authentication tokens vulnerability exists in \ncertain Ebyte gateway products. Authentication tokens used by the web \nmanagement interface are insufficiently protected during client-side \nsession handling, which…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-598"],"vendor":"Ebyte","product":"Ebyte NA111-M Firmware","affected":["na111-m_firmware 9013-2-17"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-08-28T13:50:11.030796Z"},"published":"2026-08-27","updated":"2026-10-05","sourceUpdated":"2026-10-05T19:21:04.676Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-76179","references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json"}],"tags":["cve.org"],"epss":0.00652,"epssPercentile":0.49469,"ingestedAt":"2026-10-05T20:32:56.663Z","slug":"CVE-2026-76179","body":"## Overview\n\nAn improper protection of authentication tokens vulnerability exists in \ncertain Ebyte gateway products. Authentication tokens used by the web \nmanagement interface are insufficiently protected during client-side \nsession handling, which may allow an attacker with access to exposed \nsession information to obtain and reuse a valid token. Successful \nexploitation could allow an attacker to impersonate an authenticated \nuser and gain unauthorized access to device management functionality.\n\n## Affected\n\n- `na111-m_firmware 9013-2-17`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n### Workarounds\n\nEbyte acknowledged receipt of the reported vulnerabilities and indicated\n that a patch was under development. However, the vendor has not \nresponded to subsequent requests for coordination, and CISA has not been\n informed of the status or availability of the patch. Users are \nencouraged to reach out to Ebyte for more information.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}