CVE-2026-73839
Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk of credential compromise through visual or remote observation. This undermines the confidentiality of device access.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.1
- CVSS vector
- CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.15%
- CWE
- CWE-522
- Published
- 2026-08-27
- Last modified
- 2026-08-28
Affected products
- Ebyte Ebyte NE2-D11 Firmware
Weakness type
Related vulnerabilities
- CVE-2026-88013 — rclone: http backend forwards custom/auth headers to a different host on redirect
- CVE-2026-69805 — .NET Elevation of Privilege Vulnerability
- CVE-2026-64918 — Microsoft Office Spoofing Vulnerability
- CVE-2026-81381 — GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
- CVE-2026-77909 — Azure CycleCloud Information Disclosure Vulnerability
- CVE-2026-82070 — Insufficiently Protected Credentials in MongoDB Server Diagnostic Reporting Interface
- CVE-2026-86600 — Workload identity attestation generated before login host validation in Snowflake drivers
- CVE-2026-86726 — AVideo through 29.0 Information Disclosure via restreamsActive.json.php