CVE-2026-76179CWE-598

CVE-2026-76179

Critical · published August 28, 2026

CVSS v3.1
9.8
EPSS
0%
Percentile
36.5
In the wild
Unconfirmed
What it is

An improper protection of authentication tokens vulnerability exists in

certain Ebyte gateway products. Authentication tokens used by the web

management interface are insufficiently protected during client-side

session handling, which may allow an attacker with access to exposed

session information to obtain and reuse a valid token. Successful

exploitation could allow an attacker to impersonate an authenticated

user and gain unauthorized access to device management functionality.

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
9.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00434 · 36.5th percentile
Weakness
CWE-598 · Use of HTTP Request With Sensitive Query String
Published
2026-08-28T04:18Z
References (2)
EPSS history
Timeline
  • 29 AUG 09:35Z
    EPSS moved — → 0%
    epss
  • 27 AUG 21:22Z
    Ebyte NE2-D11 Use of GET Request Method With Sensitive Query Strings
    cvelistv5