---
id: CVE-2026-76179
title: Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings
summary: |-
  An improper protection of authentication tokens vulnerability exists in 
  certain Ebyte gateway products. Authentication tokens used by the web 
  management interface are insufficiently protected during client-side 
  session handling, which…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-598
vendor: Ebyte
product: Ebyte NA111-M Firmware
affected:
  - na111-m_firmware 9013-2-17
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-08-28T13:50:11.030796Z'
published: '2026-08-27'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:21:04.676Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-76179'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06'
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
tags:
  - cve.org
epss: 0.00652
epssPercentile: 0.49469
ingestedAt: '2026-10-05T20:32:56.663Z'
---

## Overview

An improper protection of authentication tokens vulnerability exists in 
certain Ebyte gateway products. Authentication tokens used by the web 
management interface are insufficiently protected during client-side 
session handling, which may allow an attacker with access to exposed 
session information to obtain and reuse a valid token. Successful 
exploitation could allow an attacker to impersonate an authenticated 
user and gain unauthorized access to device management functionality.

## Affected

- `na111-m_firmware 9013-2-17`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated
 that a patch was under development. However, the vendor has not 
responded to subsequent requests for coordination, and CISA has not been
 informed of the status or availability of the patch. Users are 
encouraged to reach out to Ebyte for more information.
