CVE-2026-71187CWE-603
CVE-2026-71187
Critical · published August 28, 2026
What it is
The Ebyte device relies on client side authentication logic that can be
reproduced by unauthenticated users. An attacker may generate valid
authentication requests and bypass authentication to obtain
administrative access to the device.
The record
Technical detail
- CVSS v3.1
- 9.8 · CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS v4.0
- 9.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS
- 0.00521 · 42.4th percentile
- Weakness
- CWE-603 · Use of Client-Side Authentication
- Published
- 2026-08-28T04:18Z
References (2)
EPSS history
Timeline