---
id: CVE-2026-75814
title: Ebyte NA111-M Cross-Site Request Forgery
summary: |-
  The Ebyte device does not adequately verify the origin or authenticity of 
  requests submitted to the web management interface. An unauthenticated 
  remote attacker could persuade an authenticated administrator to visit a
   crafted page, ca…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-352
vendor: Ebyte
product: Ebyte NA111-M Firmware
affected:
  - na111-m_firmware 9013-2-17
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-28T13:49:45.761914Z'
published: '2026-08-27'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:21:33.592Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-75814'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06'
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
tags:
  - cve.org
epss: 0.00247
epssPercentile: 0.1456
ingestedAt: '2026-10-05T20:32:56.662Z'
---

## Overview

The Ebyte device does not adequately verify the origin or authenticity of 
requests submitted to the web management interface. An unauthenticated 
remote attacker could persuade an authenticated administrator to visit a
 crafted page, causing unauthorized configuration changes or a 
disruption of device availability.

## Affected

- `na111-m_firmware 9013-2-17`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated
 that a patch was under development. However, the vendor has not 
responded to subsequent requests for coordination, and CISA has not been
 informed of the status or availability of the patch. Users are 
encouraged to reach out to Ebyte for more information.
