# CVE-2026-73819

## Summary

- **CVE ID:** CVE-2026-73819
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-1390
- **Published:** Aug 31, 2026
- **Last Modified:** Sep 1, 2026

## Description

The affected Ebyte 

product's vendor configuration utility permits access to administrative 
functions without verifying the operator's identity under certain 
credential conditions. An unauthenticated attacker on the adjacent 
network could modify critical settings or change access credentials, 
potentially preventing legitimate administrators from managing the 
device.

## Affected Products

- Ebyte — Ebyte NA111-M Firmware (9013-2-17)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06)
- [CNA](https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.53%
- **EPSS Percentile:** 42.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._