---
id: CVE-2026-76945
title: Ebyte NE2-D11 Use of Client-Side Authentication
summary: |-
  The affected Ebyte device relies on client-managed authentication tokens
   without sufficient server-side validation. An attacker may replay or 
  manipulate authentication tokens to gain unauthorized access to 
  administrative functionality.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-603
vendor: Ebyte
product: Ebyte NE2-D11 Firmware
affected:
  - ne2-d11_firmware FW-9167-0-11
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-28T13:49:14.279908Z'
published: '2026-08-27'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:29:57.570Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-76945'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06'
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
tags:
  - cve.org
epss: 0.00504
epssPercentile: 0.4094
ingestedAt: '2026-10-05T20:32:56.658Z'
---

## Overview

The affected Ebyte device relies on client-managed authentication tokens
 without sufficient server-side validation. An attacker may replay or 
manipulate authentication tokens to gain unauthorized access to 
administrative functionality.

## Affected

- `ne2-d11_firmware FW-9167-0-11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated
 that a patch was under development. However, the vendor has not 
responded to subsequent requests for coordination, and CISA has not been
 informed of the status or availability of the patch. Users are 
encouraged to reach out to Ebyte for more information.
