What happened
On 2026-08-27, CISA released an advisory (ICSA-26-239-05) concerning the Ebyte NA111-M device. The advisory identifies multiple vulnerabilities in firmware version 9013-2-17, listing 13 CVEs: CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, and CVE-2026-77977. The advisory notes that successful exploitation could allow an attacker to fully compromise the device. The vulnerabilities are rated with a CVSS v3 base score of 9.8, indicating critical severity.
The advisory also mentions specific vulnerability types, including Missing Authentication for Critical Function, Use of GET Request Method With Sensitive Query Strings, and Cross-Site Request Forgery (CSRF). These issues could be exploited remotely, potentially leading to unauthorized access and control.
Why it matters
The high severity of these vulnerabilities, combined with the potential for full device compromise, poses a significant risk to affected systems. Organizations using the Ebyte NA111-M with firmware 9013-2-17 should take immediate action to apply any available patches or mitigations. The advisory underscores the importance of monitoring ICS advisories for critical infrastructure components.