CVE-2026-75548CWE-1021

CVE-2026-75548

Medium · published August 28, 2026

CVSS v3.1
5.4
EPSS
0%
Percentile
6.7
In the wild
Unconfirmed
What it is

The affected Ebyte device web management interface does not restrict the

interface from being rendered within an external frame. An

unauthenticated remote attacker could use a crafted webpage to mislead

an authenticated administrator into initiating unintended configuration

changes or disruptive actions.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS
0.00171 · 6.7th percentile
Weakness
CWE-1021 · Improper Restriction of Rendered UI Layers or Frames
Published
2026-08-28T04:18Z
References (2)
EPSS history
Timeline
  • 27 AUG 21:30Z
    Ebyte NE2-D11 Improper Restriction of Rendered UI Layers or Frames
    cvelistv5