CVE-2026-73819CWE-1390

CVE-2026-73819

Critical · published August 31, 2026

CVSS v3.1
9.8
EPSS
1%
Percentile
42.8
In the wild
Unconfirmed
What it is

The affected Ebyte

product's vendor configuration utility permits access to administrative

functions without verifying the operator's identity under certain

credential conditions. An unauthenticated attacker on the adjacent

network could modify critical settings or change access credentials,

potentially preventing legitimate administrators from managing the

device.

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
9.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00528 · 42.8th percentile
Weakness
CWE-1390 · Weak Authentication
Published
2026-08-31T20:19Z
References (2)
EPSS history
Timeline
  • 02 SEP 03:39Z
    EPSS moved — → 1%
    epss
  • 31 AUG 15:28Z
    Ebyte NA111-M Weak Authentication
    cvelistv5