---
id: CVE-2026-77977
title: Ebyte NA111-M Missing Authentication for Critical Function
summary: >-
  Ebyte gateway product's vendor configuration utility does not require
  authentication before 

  allowing certain disruptive administrative actions when default 

  credentials remain configured. An unauthenticated attacker on the 

  adjacent net…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-306
vendor: Ebyte
product: Ebyte NA111-M Firmware
affected:
  - na111-m_firmware 9013-2-17
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-28T13:48:09.996285Z'
published: '2026-08-27'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:28:12.953Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-77977'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06'
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
tags:
  - cve.org
epss: 0.00367
epssPercentile: 0.28243
ingestedAt: '2026-10-05T20:32:56.659Z'
---

## Overview

Ebyte gateway product's vendor configuration utility does not require authentication before 
allowing certain disruptive administrative actions when default 
credentials remain configured. An unauthenticated attacker on the 
adjacent network could reboot the device or restore factory settings, 
resulting in a loss of configuration and service availability.

## Affected

- `na111-m_firmware 9013-2-17`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Ebyte acknowledged receipt of the reported vulnerabilities and indicated
 that a patch was under development. However, the vendor has not 
responded to subsequent requests for coordination, and CISA has not been
 informed of the status or availability of the patch. Users are 
encouraged to reach out to Ebyte for more information.
