---
id: CVE-2026-75548
title: Ebyte NA111-M Improper Restriction of Rendered UI Layers or Frames
summary: |-
  The affected Ebyte device web management interface does not restrict the
   interface from being rendered within an external frame. An 
  unauthenticated remote attacker could use a crafted webpage to mislead 
  an authenticated administrator …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-1021
vendor: Ebyte
product: Ebyte NA111-M Firmware
affected:
  - na111-m_firmware 9013-2-17
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-28T13:49:33.347547Z'
published: '2026-08-27'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:24:37.557Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-75548'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06'
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
tags:
  - cve.org
epss: 0.00291
epssPercentile: 0.19677
ingestedAt: '2026-10-05T20:32:56.661Z'
---

## Overview

The affected Ebyte device web management interface does not restrict the
 interface from being rendered within an external frame. An 
unauthenticated remote attacker could use a crafted webpage to mislead 
an authenticated administrator into initiating unintended configuration 
changes or disruptive actions.

## Affected

- `na111-m_firmware 9013-2-17`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated
 that a patch was under development. However, the vendor has not 
responded to subsequent requests for coordination, and CISA has not been
 informed of the status or availability of the patch. Users are 
encouraged to reach out to Ebyte for more information.
