criticalOther

Ebyte NA111-M Multiple Vulnerabilities (13 CVEs, ICSA-26-239-05)

First seen Aug 29, 2026 · Updated Aug 29, 2026 · CVSS 9.8

ICSIoTcellular-gatewayauthentication-bypassCSRFcleartext-credentialsweak-cryptoMQTTunpatchedno-vendor-fix

The Ebyte NA111-M cellular/MQTT gateway (firmware 9013-2-17) contains 13 vulnerabilities, several rated critical (CVSS 9.8), including missing authentication, client-side authentication bypass, weak cryptographic hashing, and cleartext transmission/storage of credentials including MQTT traffic. Combined, these flaws allow unauthenticated remote attackers to fully compromise the device, gaining administrative control, intercepting or replaying credentials, and disrupting availability. Ebyte has not delivered a patch despite CISA coordination attempts, leaving deployed units permanently exposed absent compensating network controls.

Technical Analysis

The advisory covers 13 CVEs affecting Ebyte NA111-M firmware 9013-2-17, rooted in fundamental authentication and cryptographic design failures (CWE-306, CWE-603, CWE-1390, CWE-327, CWE-319, CWE-312, CWE-352, CWE-1021, CWE-862, CWE-307, CWE-598). Critical-rated issues include missing authentication for administrative functions (CVE-2026-73125, CVSS 9.8), client-side authentication logic that can be reproduced to bypass login (CVE-2026-71187, CVSS 9.8), use of a broken/weak hashing algorithm in authentication (CVE-2026-76133, CVSS 9.8), weak default-credential authentication in the vendor config utility (CVE-2026-73819, CVSS 9.8), and cleartext transmission of MQTT credentials and control traffic (CVE-2026-69658, CVSS 9.8), any of which alone could grant an unauthenticated network attacker full device takeover. Additional high/medium issues (CSRF, clickjacking via unrestricted framing, brute-force with no rate limiting, cleartext config export, unauthenticated factory reset) compound the risk of credential theft, configuration tampering, and denial of service. These are IIoT/edge gateway devices frequently used to bridge sensors, controllers, and MQTT message brokers into cloud or automation pipelines; where such gateways feed telemetry into AI-driven monitoring, RAG-based operational dashboards, or autonomous agent decision loops, intercepted MQTT credentials or a compromised gateway could allow attackers to inject falsified data or pivot toward systems hosting agent orchestration and API keys, making this agent-relevant for organizations using these devices in automated/agentic industrial or IoT data pipelines.

Affected Systems

Ebyte NA111-M cellular/IoT gateway devices running firmware version 9013-2-17; primarily IT/OT deployments using this device for MQTT-based connectivity and remote management worldwide.

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) published; this is a vulnerability disclosure, not an active campaign report.

Remediation Steps

  1. 1

    Isolate affected devices

    Ensure NA111-M gateways are not accessible from the internet; place them behind firewalls and segment from business/IT networks.

  2. 2

    Restrict remote access

    Require VPN for any remote management access, and keep VPN software patched and monitored.

  3. 3

    Change default credentials

    Immediately replace any default or weak credentials on the vendor configuration utility to reduce risk from CWE-1390 and CWE-306 issues.

  4. 4

    Monitor for vendor patch

    Contact Ebyte directly for firmware update status, as CISA has received no confirmation of an available patch; apply updates as soon as released.

  5. 5

    Secure MQTT traffic

    Enable TLS/encryption for MQTT communications where possible or use compensating network encryption (e.g., VPN tunnel) to protect credentials in transit.

  6. 6

    Protect exported configuration files

    Restrict and encrypt access to exported device configuration files, which may contain cleartext credentials.

  7. 7

    Consider device replacement

    Given the vendor's lack of responsiveness and the breadth/severity of flaws, evaluate replacing the device with a vendor that provides active security support.

CVE / Advisory IDs

CVE-2026-73125CVE-2026-76179CVE-2026-75814CVE-2026-76940CVE-2026-77966CVE-2026-73809CVE-2026-71187CVE-2026-75548CVE-2026-69658CVE-2026-76133CVE-2026-73819CVE-2026-77975CVE-2026-77977

Industries Most Exposed

Information TechnologyIndustrial Control SystemsIoT/ManufacturingCritical Infrastructure

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.