Ebyte NA111-M Gateways Face 13 Critical Flaws, No Patch
Ebyte promised CISA a patch then went dark, the second time in three days the vendor has left gateway owners with critical exposures and no mitigation path.
TL;DR
CISA published advisory ICSA-26-239-05 Wednesday detailing 13 authentication and cryptographic vulnerabilities in Ebyte NA111-M gateway firmware 9013-2-17. Nine flaws carry CVSS 9.8; all allow unauthenticated remote attackers to access or modify device configuration and disrupt availability. Ebyte acknowledged the vulnerabilities and indicated a patch was under development, then stopped responding to CISA. This is the second Ebyte advisory in three days (ICSA-26-237-06 covered NE2-D11 flaws Monday with the same vendor-silence pattern) leaving contractors, MSPs, and C3PAOs worldwide with critical exposures and no mitigation path.
CISA published ICSA-26-239-05 on Wednesday, and the pattern is already familiar: Ebyte acknowledged the vulnerabilities, promised a patch, and stopped answering the phone.
The advisory covers 13 distinct flaws in the NA111-M gateway's web management interface, all in firmware version 9013-2-17. Nine carry a CVSS v3 score of 9.8, the ceiling for remotely exploitable, unauthenticated compromise. The roster is comprehensive: missing authentication for critical functions (CVE-2026-73125), cleartext transmission of authentication tokens (CVE-2026-73809), client-side authentication that an attacker can simply bypass (CVE-2026-71187), hard-coded credentials, weak cryptographic algorithms, cleartext storage of sensitive information, and a cross-site request forgery vector that lets an attacker reconfigure the device if they can get an admin to click a link. An unauthenticated remote attacker who reaches the management interface can read or modify device configuration and disrupt availability. There's no rate limiting on authentication attempts either, so brute-forcing is on the table.
Same vendor, same silence, three days apart
This is the second CISA advisory for Ebyte products this week. On Monday, ICSA-26-237-06 documented flaws in the NE2-D11 gateway, different product line, same outcome: CISA disclosed, Ebyte acknowledged and went quiet. The NA111-M advisory repeats the same remediation language verbatim: "Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch."
For defenders, that's the operational reality. There isn't a patch. There isn't a timeline. There isn't even a commitment to cover all deployed firmware versions versus only new installations. The devices are deployed worldwide across the information technology sector, and the only mitigation CISA can offer is "users are encouraged to reach out to Ebyte for more information", which is what you say when the vendor has left the building.
For NA111-M operators: segment and monitor
If you're running NA111-M gateways in any environment where availability or configuration integrity matters, segment them from untrusted networks immediately. The web management interface shouldn't be reachable from the internet, that's true regardless of patch status, but it's the only control you can enforce right now. Monitor for unusual configuration changes or unexpected reboots. And if you're sourcing these devices for a compliance-sensitive deployment, the vendor's coordination posture over the past week is a data point worth factoring into procurement and architecture decisions.
Published ·Deep Fathom