SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73125

CRITICAL · CVSS 9.8 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The web management interface of Ebyte devices lacks consistent authentication controls, allowing unauthenticated remote attackers to access sensitive configuration data, alter device settings, or disrupt service availability. Organizations using Ebyte devices should prioritize addressing this critical vulnerability to safeguard their network infrastructure and prevent unauthorized access. Immediate action is essential to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73125
Severity
CRITICAL
CVSS
9.8
EPSS
0.53%

Original NVD Description

Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.