CVE-2026-71187
The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.52%
- CWE
- CWE-603
- Published
- 2026-08-27
- Last modified
- 2026-08-31
Affected products
- Ebyte Ebyte NE2-D11 Firmware
- Ebyte Ebyte NA111-M Firmware
Weakness type
Related vulnerabilities
- CVE-2026-66305 — Skype for Business Spoofing Vulnerability
- CVE-2026-76945 — Ebyte NE2-D11 Use of Client-Side Authentication
- CVE-2026-42098 — Authorization Bypass in Sparx Enterprise Architect
- CVE-2026-8830 — Keycloak: org.keycloak/keycloak-services: keycloak: policy bypass during webauthn credential registration via client-side javascript manipulation
- CVE-2026-40551 — Use of Client-Side Authentication in mpGabinet
- CVE-2025-30042 — Session generation possible with certificate number only
- CVE-2026-1363 — JNC|IAQS and I6 - Client-Side Enforcement of Server-Side Security
- CVE-2025-64119 — Nuvation Energy BMS Client-side Authentication