CVE-2026-71187: Ebyte NA111-M Firmware

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.

Affected products

  • Ebyte Ebyte NA111-M Firmware: version 9013-2-17 only

Published 2026-08-28. Last modified 2026-08-31.