CVE-2026-75814
Deferred Deferred - Pending Action

Unauthenticated Request Forgery in Ebyte Device Web Interface

Vulnerability report for CVE-2026-75814, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-31

Assigner: ICS-CERT

Description

The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, causing unauthorized configuration changes or a disruption of device availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-31
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ebyte csafpid-0001 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an Ebyte device that fails to properly verify the origin or authenticity of requests sent to its web management interface. An attacker could trick an authenticated administrator into visiting a malicious page, leading to unauthorized changes in device settings or causing the device to become unavailable.

Detection Guidance

This vulnerability involves unauthenticated remote attackers tricking administrators into visiting malicious pages. Detection requires monitoring web traffic to the Ebyte device's management interface for unusual requests or configuration changes. Check logs for unexpected administrative actions or connections from untrusted sources.

Impact Analysis

An attacker could exploit this to make unauthorized configuration changes to the device, potentially disrupting its operation or gaining control. This could lead to loss of device functionality, data breaches, or unauthorized access to connected systems.

Compliance Impact

This vulnerability could lead to unauthorized access or changes to sensitive data or systems, violating compliance requirements for GDPR, HIPAA, or other regulations. It may result in data breaches, loss of data integrity, or failure to meet security controls mandated by these standards.

Mitigation Strategies

Restrict access to the web management interface to trusted networks or IP addresses only. Disable remote administration if not required. Ensure administrators avoid visiting untrusted websites while logged into the device interface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75814. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart