CVE-2026-71187CWE-603

CVE-2026-71187

Critical · published August 28, 2026

CVSS v3.1
9.8
EPSS
1%
Percentile
42.4
In the wild
Unconfirmed
What it is

The Ebyte device relies on client side authentication logic that can be

reproduced by unauthenticated users. An attacker may generate valid

authentication requests and bypass authentication to obtain

administrative access to the device.

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
9.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00521 · 42.4th percentile
Weakness
CWE-603 · Use of Client-Side Authentication
Published
2026-08-28T04:18Z
References (2)
EPSS history
Timeline
  • 27 AUG 21:20Z
    Ebyte NE2-D11 Use of Client-Side Authentication
    cvelistv5