---
id: CVE-2026-73839
title: Ebyte NE2-D11 Insufficiently Protected Credentials
summary: |-
  Administrative credentials may be exposed in plaintext within the Ebyte 
  device's management interface, increasing the risk of credential 
  compromise through visual or remote observation. This undermines the 
  confidentiality of device ac…
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-522
vendor: Ebyte
product: Ebyte NE2-D11 Firmware
affected:
  - ne2-d11_firmware FW-9167-0-11
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-28T13:51:07.750453Z'
published: '2026-08-27'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:28:49.882Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-73839'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06'
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
tags:
  - cve.org
epss: 0.00204
epssPercentile: 0.09407
ingestedAt: '2026-10-05T20:32:56.659Z'
---

## Overview

Administrative credentials may be exposed in plaintext within the Ebyte 
device's management interface, increasing the risk of credential 
compromise through visual or remote observation. This undermines the 
confidentiality of device access.

## Affected

- `ne2-d11_firmware FW-9167-0-11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated
 that a patch was under development. However, the vendor has not 
responded to subsequent requests for coordination, and CISA has not been
 informed of the status or availability of the patch. Users are 
encouraged to reach out to Ebyte for more information.
