Ebyte NA111-M
Plan PatchCVSS 9.8ICS-CERT ICSA-26-239-05Aug 27, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
The Ebyte NA111-M contains multiple critical vulnerabilities (CWE-306, CWE-598, CWE-352, CWE-307, CWE-862, CWE-319, CWE-603, CWE-1021, CWE-327, CWE-1390, CWE-312) that allow unauthenticated remote attackers to fully compromise the device. The vendor acknowledged the vulnerabilities and indicated a patch was under development, but has not provided updates on patch status or availability.
What this means
What could happen
An attacker who reaches the NA111-M device over the network could execute arbitrary commands with full device privileges, potentially compromising measurements, communications, or control functions depending on how the device is integrated into your operations.
Who's at risk
Operators of Ebyte NA111-M measurement or communication devices used in water, power, or other critical infrastructure monitoring and control systems should assess the network exposure of these devices and implement compensating controls immediately.
How it could be exploited
An attacker on the network can send unauthenticated requests to the NA111-M without requiring valid credentials, exploiting flaws in authentication, data encryption, and input validation to execute arbitrary code on the device.
Prerequisites
- Network access to the NA111-M device (direct or via internal network)
- Device running firmware version 9013-2-17
remotely exploitableno authentication requiredlow complexityno patch availablecritical CVSS (9.8)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (1)
ProductAffected VersionsFix Status
NA111-M Firmware: 9013-2-179013-2-17No fix yet
Remediation & Mitigation
0/4
Do now
0/3WORKAROUNDContact Ebyte directly to determine if a patch is available and request technical guidance on remediation options
HARDENINGRestrict network access to the NA111-M using firewall rules, limiting connections to only authorized engineering and monitoring systems
HARDENINGIsolate or air-gap the NA111-M from untrusted networks if it is not essential for continuous operation
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HARDENINGMonitor network traffic to and from the NA111-M for suspicious activity and unexpected connections
CVEs (13)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/253789a4-5f91-44cb-9f99-a3cb11038f62Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.