AllCyberNews

CVE-2026-76179

Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings

CVSS 9.3 critical · Ebyte Ebyte NA111-M Firmware · published 2026-08-27

An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality.

Coverage 1 source

  1. 2026-08-27 CISA Cybersecurity Advisories critical Ebyte NA111-M

    Multiple vulnerabilities in Ebyte NA111-M could allow full device compromise.

Mentioned with

CVE-2026-69658 CVE-2026-71187 CVE-2026-73125 CVE-2026-76133 CVE-2026-76940 CVE-2026-77966 CVE-2026-77975 CVE-2026-77977

Also covered