Ebyte NA111-M Multiple Vulnerabilities (13 CVEs, ICSA-26-239-05)
First seen Aug 29, 2026 · Updated Aug 29, 2026 · CVSS 9.8
The Ebyte NA111-M cellular/MQTT gateway (firmware 9013-2-17) contains 13 vulnerabilities, several rated critical (CVSS 9.8), including missing authentication, client-side authentication bypass, weak cryptographic hashing, and cleartext transmission/storage of credentials including MQTT traffic. Combined, these flaws allow unauthenticated remote attackers to fully compromise the device, gaining administrative control, intercepting or replaying credentials, and disrupting availability. Ebyte has not delivered a patch despite CISA coordination attempts, leaving deployed units permanently exposed absent compensating network controls.
Technical Analysis
The advisory covers 13 CVEs affecting Ebyte NA111-M firmware 9013-2-17, rooted in fundamental authentication and cryptographic design failures (CWE-306, CWE-603, CWE-1390, CWE-327, CWE-319, CWE-312, CWE-352, CWE-1021, CWE-862, CWE-307, CWE-598). Critical-rated issues include missing authentication for administrative functions (CVE-2026-73125, CVSS 9.8), client-side authentication logic that can be reproduced to bypass login (CVE-2026-71187, CVSS 9.8), use of a broken/weak hashing algorithm in authentication (CVE-2026-76133, CVSS 9.8), weak default-credential authentication in the vendor config utility (CVE-2026-73819, CVSS 9.8), and cleartext transmission of MQTT credentials and control traffic (CVE-2026-69658, CVSS 9.8), any of which alone could grant an unauthenticated network attacker full device takeover. Additional high/medium issues (CSRF, clickjacking via unrestricted framing, brute-force with no rate limiting, cleartext config export, unauthenticated factory reset) compound the risk of credential theft, configuration tampering, and denial of service. These are IIoT/edge gateway devices frequently used to bridge sensors, controllers, and MQTT message brokers into cloud or automation pipelines; where such gateways feed telemetry into AI-driven monitoring, RAG-based operational dashboards, or autonomous agent decision loops, intercepted MQTT credentials or a compromised gateway could allow attackers to inject falsified data or pivot toward systems hosting agent orchestration and API keys, making this agent-relevant for organizations using these devices in automated/agentic industrial or IoT data pipelines.
Affected Systems
Ebyte NA111-M cellular/IoT gateway devices running firmware version 9013-2-17; primarily IT/OT deployments using this device for MQTT-based connectivity and remote management worldwide.
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) published; this is a vulnerability disclosure, not an active campaign report.
Remediation Steps
- 1
Isolate affected devices
Ensure NA111-M gateways are not accessible from the internet; place them behind firewalls and segment from business/IT networks.
- 2
Restrict remote access
Require VPN for any remote management access, and keep VPN software patched and monitored.
- 3
Change default credentials
Immediately replace any default or weak credentials on the vendor configuration utility to reduce risk from CWE-1390 and CWE-306 issues.
- 4
Monitor for vendor patch
Contact Ebyte directly for firmware update status, as CISA has received no confirmation of an available patch; apply updates as soon as released.
- 5
Secure MQTT traffic
Enable TLS/encryption for MQTT communications where possible or use compensating network encryption (e.g., VPN tunnel) to protect credentials in transit.
- 6
Protect exported configuration files
Restrict and encrypt access to exported device configuration files, which may contain cleartext credentials.
- 7
Consider device replacement
Given the vendor's lack of responsiveness and the breadth/severity of flaws, evaluate replacing the device with a vendor that provides active security support.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.