Sceawere
Vulnerability Detail
CVE-2026-73809UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ebyte Gateway Cleartext Transmission Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 2h ago
- Vendor
- Ebyte
- Product
- Ebyte NE2-D11 Firmware
- Attack Type
- CWE-319 Cleartext Transmission of Sensitive Information
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful exploitation could result in disclosure of sensitive information and unauthorized access to device management functionality.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-28T00:18:11.410Z",
"pubdate": "2026-08-28T00:18:11.410Z",
"executiveSummary": "This vulnerability involves the transmission of sensitive information in cleartext within the web management interface of specific Ebyte gateway products. The failure to implement transport-layer encryption, such as TLS/SSL, exposes authentication credentials and session identifiers to unauthorized interception.\nThe vulnerability type is categorized as cleartext transmission of sensitive information, presenting a significant risk to the confidentiality and integrity of device management operations. An attacker positioned on the same network segment can perform passive sniffing or active man-in-the-middle (MITM) attacks to capture sensitive data streams.\nThe impact includes the disclosure of administrative credentials, session tokens, and configuration details, potentially leading to unauthorized access to the device management interface. Such access allows an attacker to modify device settings, intercept routed traffic, or compromise the broader network connected through the gateway. Successful exploitation requires network proximity but does not necessitate prior authentication to the management interface, as the vulnerability resides at the transport layer of the communication protocol.",
"technicalDetails": "The vulnerability originates from the lack of mandatory transport-layer encryption (e.g., HTTPS/TLS) within the web-based management interface of affected Ebyte gateway products. When administrative users interact with the device via a web browser, the gateway processes requests over plain HTTP, transmitting all payloads—including usernames, passwords, and session cookies—in cleartext.\nThe attack flow begins with an attacker gaining network access to the local area network or a segment where the management interface is exposed. Utilizing packet-capturing utilities like Wireshark or tcpdump, the attacker monitors traffic directed toward the device's management IP address. Because the traffic lacks encryption, the attacker can extract authentication headers or session identifiers directly from the TCP payload stream. In an active exploitation scenario, an attacker could utilize ARP spoofing to perform a man-in-the-middle (MITM) attack, forcing the user's traffic through a node controlled by the attacker to decrypt and inspect intercepted packets in real-time.\nThe vulnerable component is the embedded web server/management interface stack that fails to negotiate secure channels. Once the authentication information is intercepted, the attacker can replay the captured session tokens to bypass the login requirement or use the harvested credentials to authenticate legitimately. This unauthorized access grants the attacker full control over the gateway's management functionality, including the ability to alter network routing tables, modify firewall configurations, or push malicious firmware updates if supported by the management interface.\nPost-exploitation impact extends beyond the immediate device compromise; since these gateways often serve as critical network infrastructure, an attacker can leverage administrative control to facilitate lateral movement, conduct reconnaissance on internal assets, or execute man-in-the-middle attacks on the traffic passing through the gateway. The exposure of sensitive management information provides the attacker with persistent control over the device and its associated network segments, effectively neutralizing the security perimeter established by the gateway. There are no technical requirements for the attacker to be authenticated to the management interface to perform the interception, as the information is exposed during the initial handshake and login request phase."
}