# CVE-2026-73839

## Summary

- **CVE ID:** CVE-2026-73839
- **Severity:** MEDIUM
- **CVSS Score:** 5.1 (CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-522
- **Published:** Aug 27, 2026
- **Last Modified:** Aug 28, 2026

## Description

Administrative credentials may be exposed in plaintext within the Ebyte 
device's management interface, increasing the risk of credential 
compromise through visual or remote observation. This undermines the 
confidentiality of device access.

## Affected Products

- Ebyte — Ebyte NE2-D11 Firmware (FW-9167-0-11)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06)
- [CNA](https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._