---
id: CVE-2026-77975
title: Ebyte NA111-M Cleartext Storage of Sensitive Information
summary: |-
  The affected Ebyte 

  product exports administrative credentials and other 
  sensitive configuration information without adequate protection. An 
  unauthenticated attacker on the adjacent network who can obtain an 
  exported configuration fi…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-312
vendor: Ebyte
product: Ebyte NE2-D11 Firmware
affected:
  - ne2-d11_firmware 9013-2-17
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-31T15:51:22.810136Z'
published: '2026-08-31'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:27:44.696Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-77975'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06'
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
tags:
  - cve.org
epss: 0.00181
epssPercentile: 0.06999
ingestedAt: '2026-10-05T20:32:56.660Z'
---

## Overview

The affected Ebyte 

product exports administrative credentials and other 
sensitive configuration information without adequate protection. An 
unauthenticated attacker on the adjacent network who can obtain an 
exported configuration file could recover valid credentials and use them
 to access the device or similarly configured systems.

## Affected

- `ne2-d11_firmware 9013-2-17`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated
 that a patch was under development. However, the vendor has not 
responded to subsequent requests for coordination, and CISA has not been
 informed of the status or availability of the patch. Users are 
encouraged to reach out to Ebyte for more information.
