{"id":"CVE-2026-77975","title":"Ebyte NA111-M Cleartext Storage of Sensitive Information","summary":"The affected Ebyte \n\nproduct exports administrative credentials and other \nsensitive configuration information without adequate protection. An \nunauthenticated attacker on the adjacent network who can obtain an \nexported configuration fi…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cvssSource":"cna","cwe":["CWE-312"],"vendor":"Ebyte","product":"Ebyte NE2-D11 Firmware","affected":["ne2-d11_firmware 9013-2-17"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-31T15:51:22.810136Z"},"published":"2026-08-31","updated":"2026-10-05","sourceUpdated":"2026-10-05T19:27:44.696Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-77975","references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json"}],"tags":["cve.org"],"epss":0.00181,"epssPercentile":0.06999,"ingestedAt":"2026-10-05T20:32:56.660Z","slug":"CVE-2026-77975","body":"## Overview\n\nThe affected Ebyte \n\nproduct exports administrative credentials and other \nsensitive configuration information without adequate protection. An \nunauthenticated attacker on the adjacent network who can obtain an \nexported configuration file could recover valid credentials and use them\n to access the device or similarly configured systems.\n\n## Affected\n\n- `ne2-d11_firmware 9013-2-17`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n### Workarounds\n\nEbyte acknowledged receipt of the reported vulnerabilities and indicated\n that a patch was under development. However, the vendor has not \nresponded to subsequent requests for coordination, and CISA has not been\n informed of the status or availability of the patch. Users are \nencouraged to reach out to Ebyte for more information.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}