Ebyte NE2-D11

Plan PatchCVSS 9.8ICS-CERT ICSA-26-237-06Aug 25, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

The Ebyte NE2-D11 device contains multiple vulnerabilities in authentication, encryption, and session management that allow an unauthenticated attacker on the network to gain administrative access, disclose sensitive configuration, modify device settings, hijack authenticated sessions, and disrupt device operation. The vulnerabilities affect firmware version FW-9167-0-11. Ebyte has acknowledged the issues and indicated a patch is under development, but has not provided a timeline or confirmed patch availability.

What this means
What could happen
An attacker with network access could gain administrative control of the NE2-D11 device, read sensitive configuration data, modify network or process settings, or take the device offline entirely. This could disrupt communications or control functions across connected industrial systems.
Who's at risk
Organizations using Ebyte NE2-D11 devices as network controllers, industrial gateways, or data acquisition units in water systems, power distribution, manufacturing, or other OT environments should implement compensating controls immediately, as there is no vendor patch available yet.
How it could be exploited
An attacker on the network can send unauthenticated requests to the NE2-D11 to bypass authentication, intercept unencrypted session tokens, or inject commands that alter device configuration. No special credentials or complexity is required; the vulnerabilities are remotely accessible on the network.
Prerequisites
  • Network access to the NE2-D11 device
  • No authentication required for initial exploit
  • Device running firmware FW-9167-0-11
remotely exploitableno authentication requiredlow complexityno patch availablecritical severity (CVSS 9.8)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (1)
ProductAffected VersionsFix Status
NE2-D11 Firmware: FW-9167-0-11FW-9167-0-11No fix yet
Remediation & Mitigation
0/5
Do now
0/3
HOTFIXContact Ebyte directly to request status of the security patch and timeline for availability
HARDENINGIf the device is used in critical operations, implement network segmentation to restrict access to the NE2-D11 to only authorized engineering workstations and control systems that absolutely require it
WORKAROUNDDeploy a firewall rule to block inbound connections from untrusted networks to the NE2-D11 management interface
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HARDENINGMonitor the device for unexpected configuration changes or administrative access attempts
HOTFIXApply the firmware patch from Ebyte as soon as it becomes available
API: /api/v1/advisories/9c16684d-7eb8-4b6a-874e-90091e0abb09

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Ebyte NE2-D11 | CVSS 9.8 - OTPulse