CVE-2026-71187
Deferred Deferred - Pending Action

Authentication Bypass in Ebyte Device

Vulnerability report for CVE-2026-71187, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-31

Assigner: ICS-CERT

Description

The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-31
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ebyte csafpid-0001 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-603 A client/server product performs authentication within client code but not in server code, allowing server-side authentication to be bypassed via a modified client that omits the authentication check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves client-side authentication logic in an Ebyte device that can be bypassed by unauthenticated users. An attacker can generate valid authentication requests to gain administrative access to the device without proper credentials.

Detection Guidance

Detecting this vulnerability requires checking for unauthenticated administrative access to Ebyte CSAFPID-0001 devices. Monitor network traffic for unexpected administrative requests or sessions originating from unauthorized sources. Inspect device logs for unusual authentication attempts or administrative actions performed without valid credentials.

Impact Analysis

An attacker exploiting this vulnerability could gain full administrative control over the device. This may allow unauthorized access to sensitive data, modification of device configurations, session hijacking, or disruption of device operations.

Compliance Impact

This vulnerability could lead to unauthorized access and exposure of sensitive data, violating compliance requirements for data protection and security in standards like GDPR and HIPAA. Organizations may face legal and regulatory penalties due to compromised data integrity and confidentiality.

Mitigation Strategies

Immediately isolate affected devices from untrusted networks. Restrict network exposure by placing devices behind firewalls and using secure remote access methods like VPNs. Contact Ebyte for patch availability and apply updates once released. Monitor for unauthorized access attempts and review device configurations for suspicious changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71187. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart