# CVE-2026-77975

## Summary

- **CVE ID:** CVE-2026-77975
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-312
- **Published:** Aug 31, 2026
- **Last Modified:** Sep 1, 2026

## Description

The affected Ebyte 

product exports administrative credentials and other 
sensitive configuration information without adequate protection. An 
unauthenticated attacker on the adjacent network who can obtain an 
exported configuration file could recover valid credentials and use them
 to access the device or similarly configured systems.

## Affected Products

- Ebyte — Ebyte NE2-D11 Firmware (9013-2-17)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06)
- [CNA](https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 7.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._