---
id: CVE-2026-76940
title: Ebyte NA111-M Improper Restriction of Excessive Authentication Attempts
summary: |-
  The affected Ebyte device does not restrict repeated authentication 
  attempts through rate limiting or account lockout mechanisms. This could
   allow an attacker to perform automated authentication attacks against 
  deployments that rely o…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-307
vendor: Ebyte
product: Ebyte NA111-M Firmware
affected:
  - na111-m_firmware 9013-2-17
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-28T13:49:55.550166Z'
published: '2026-08-27'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:21:57.713Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-76940'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06'
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
tags:
  - cve.org
epss: 0.00504
epssPercentile: 0.4094
ingestedAt: '2026-10-05T20:32:56.663Z'
---

## Overview

The affected Ebyte device does not restrict repeated authentication 
attempts through rate limiting or account lockout mechanisms. This could
 allow an attacker to perform automated authentication attacks against 
deployments that rely on password based authentication.

## Affected

- `na111-m_firmware 9013-2-17`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated
 that a patch was under development. However, the vendor has not 
responded to subsequent requests for coordination, and CISA has not been
 informed of the status or availability of the patch. Users are 
encouraged to reach out to Ebyte for more information.
