Ebyte NE2-D11
The Ebyte NE2-D11 device contains multiple vulnerabilities in authentication, encryption, and session management that allow an unauthenticated attacker on the network to gain administrative access, disclose sensitive configuration, modify device settings, hijack authenticated sessions, and disrupt device operation. The vulnerabilities affect firmware version FW-9167-0-11. Ebyte has acknowledged the issues and indicated a patch is under development, but has not provided a timeline or confirmed patch availability.
- Network access to the NE2-D11 device
- No authentication required for initial exploit
- Device running firmware FW-9167-0-11
Patching may require device reboot — plan for process interruption
/api/v1/advisories/9c16684d-7eb8-4b6a-874e-90091e0abb09Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.