CVE-2026-69658: Ebyte NA111-M Firmware

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.

Affected products

  • Ebyte Ebyte NA111-M Firmware: version 9013-2-17 only

Published 2026-08-28. Last modified 2026-08-31.