---
id: CVE-2026-73819
title: Ebyte NA111-M Weak Authentication
summary: "The affected\_Ebyte \n\nproduct's vendor configuration utility permits access to administrative \nfunctions without verifying the operator's identity under certain \ncredential conditions. An unauthenticated attacker on the adjacent \nnetwork …"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-1390
vendor: Ebyte
product: Ebyte NA111-M Firmware
affected:
  - na111-m_firmware 9013-2-17
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-31T15:50:25.722002Z'
published: '2026-08-31'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:26:52.632Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-73819'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06'
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
tags:
  - cve.org
epss: 0.00528
epssPercentile: 0.42722
ingestedAt: '2026-10-05T20:32:56.659Z'
---

## Overview

The affected Ebyte 

product's vendor configuration utility permits access to administrative 
functions without verifying the operator's identity under certain 
credential conditions. An unauthenticated attacker on the adjacent 
network could modify critical settings or change access credentials, 
potentially preventing legitimate administrators from managing the 
device.

## Affected

- `na111-m_firmware 9013-2-17`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated
 that a patch was under development. However, the vendor has not 
responded to subsequent requests for coordination, and CISA has not been
 informed of the status or availability of the patch. Users are 
encouraged to reach out to Ebyte for more information.
