CISA Issues Advisory for Multiple Critical Vulnerabilities in Ebyte NE2-D11 Firmware
Four CVEs identified affecting web management interface; vendor patch status unconfirmed
Key Takeaways
- CISA advisory ICSA-26-237-06 discloses four vulnerabilities in Ebyte NE2-D11 firmware FW-9167-0-11.
- CVSS scores range from 4.6 to 9.8, with the most critical flaw allowing unauthenticated remote administrative access.
- Ebyte has acknowledged the issues but has not coordinated patch development with CISA; no patch is currently available.
- Affected products are deployed worldwide; organizations should contact Ebyte for patch status and mitigation guidance.
- No confirmed active exploitation has been reported, but the unauthenticated nature of the flaws increases risk.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


