SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73819

CRITICAL · CVSS 9.8 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability in the Ebyte product's vendor configuration utility allows unauthorized access to administrative functions without proper identity verification, particularly under specific credential conditions. This flaw enables an unauthenticated attacker on the adjacent network to alter critical settings or change access credentials, potentially locking out legitimate administrators. Organizations using Ebyte products should prioritize addressing this vulnerability to safeguard their network management capabilities.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73819
Severity
CRITICAL
CVSS
9.8
EPSS
0.53%

Original NVD Description

The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing legitimate administrators from managing the device.