ne2-d11_firmware vulnerabilities
CVEs whose affected-version data names the ne2-d11_firmware package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-77975Medium· 6.5Ebyte NA111-M Cleartext Storage of Sensitive Information
The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration fi…
CVE-2026-75813High· 7.5Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings
Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise of device functionality.
CVE-2026-73839Medium· 4.6Ebyte NE2-D11 Insufficiently Protected Credentials
Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk of credential compromise through visual or remote observation. This undermines the confidentiality of device ac…
CVE-2026-76945High· 7.5Ebyte NE2-D11 Use of Client-Side Authentication
The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access to administrative functionality.