{"id":"CVE-2026-77977","title":"Ebyte NA111-M Missing Authentication for Critical Function","summary":"Ebyte gateway product's vendor configuration utility does not require authentication before \nallowing certain disruptive administrative actions when default \ncredentials remain configured. An unauthenticated attacker on the \nadjacent net…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","cvssSource":"cna","cwe":["CWE-306"],"vendor":"Ebyte","product":"Ebyte NA111-M Firmware","affected":["na111-m_firmware 9013-2-17"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-28T13:48:09.996285Z"},"published":"2026-08-27","updated":"2026-10-05","sourceUpdated":"2026-10-05T19:28:12.953Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-77977","references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json"}],"tags":["cve.org"],"epss":0.00367,"epssPercentile":0.28243,"ingestedAt":"2026-10-05T20:32:56.659Z","slug":"CVE-2026-77977","body":"## Overview\n\nEbyte gateway product's vendor configuration utility does not require authentication before \nallowing certain disruptive administrative actions when default \ncredentials remain configured. An unauthenticated attacker on the \nadjacent network could reboot the device or restore factory settings, \nresulting in a loss of configuration and service availability.\n\n## Affected\n\n- `na111-m_firmware 9013-2-17`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n### Workarounds\n\nEbyte acknowledged receipt of the reported vulnerabilities and indicated\n that a patch was under development. However, the vendor has not \nresponded to subsequent requests for coordination, and CISA has not been\n informed of the status or availability of the patch. Users are \nencouraged to reach out to Ebyte for more information.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}