---
id: CVE-2026-76133
title: Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm
summary: "The affected\_Ebyte \n\nproduct\n uses a deprecated hashing algorithm in an authentication-related \noperation. Under conditions where an attacker can manipulate or predict \nthe authentication exchange, the weak construction may reduce the \na…"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-327
vendor: Ebyte
product: Ebyte NA111-M Firmware
affected:
  - na111-m_firmware 9013-2-17
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-08-31T15:49:59.914340Z'
published: '2026-08-31'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:26:19.802Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-76133'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06'
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
tags:
  - cve.org
epss: 0.00397
epssPercentile: 0.31557
ingestedAt: '2026-10-05T20:32:56.661Z'
---

## Overview

The affected Ebyte 

product
 uses a deprecated hashing algorithm in an authentication-related 
operation. Under conditions where an attacker can manipulate or predict 
the authentication exchange, the weak construction may reduce the 
assurance provided by the authentication mechanism and facilitate 
unauthorized access.

## Affected

- `na111-m_firmware 9013-2-17`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated
 that a patch was under development. However, the vendor has not 
responded to subsequent requests for coordination, and CISA has not been
 informed of the status or availability of the patch. Users are 
encouraged to reach out to Ebyte for more information.
