CRITICAL 9.3 NVD
CVE-2026-71187
The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication req
The Ebyte device relies on client side authentication logic that can be
reproduced by unauthenticated users. An attacker may generate valid
authentication requests and bypass authentication to obtain
administrative access to the device.
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-28 via NVD.
Risk Timeline
CVE Disclosed2026-08-28 · -1 days ago
Remediation Resources
vulnfeed aggregates 11380 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.