---
id: CVE-2026-73809
title: Ebyte NA111-M Cleartext Transmission of Sensitive Information
summary: |-
  A cleartext transmission of sensitive information vulnerability exists 
  in certain Ebyte gateway products. The web management interface does not
   adequately protect sensitive communications using transport-layer 
  encryption. An attacker …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-319
vendor: Ebyte
product: Ebyte NA111-M Firmware
affected:
  - na111-m_firmware 9013-2-17
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-28T13:56:04.522476Z'
published: '2026-08-27'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:22:57.999Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-73809'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06'
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
tags:
  - cve.org
epss: 0.00223
epssPercentile: 0.11759
ingestedAt: '2026-10-05T20:32:56.662Z'
---

## Overview

A cleartext transmission of sensitive information vulnerability exists 
in certain Ebyte gateway products. The web management interface does not
 adequately protect sensitive communications using transport-layer 
encryption. An attacker with access to network traffic could intercept 
authentication or session-related information transmitted between a user
 and the affected device. Successful exploitation could result in 
disclosure of sensitive information and unauthorized access to device 
management functionality.

## Affected

- `na111-m_firmware 9013-2-17`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated
 that a patch was under development. However, the vendor has not 
responded to subsequent requests for coordination, and CISA has not been
 informed of the status or availability of the patch. Users are 
encouraged to reach out to Ebyte for more information.
