CVE-2026-76945
Deferred Deferred - Pending Action

Authentication Token Replay in Ebyte Device

Vulnerability report for CVE-2026-76945, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-31

Assigner: ICS-CERT

Description

The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access to administrative functionality.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-31
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ebyte csafpid-0001 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-603 A client/server product performs authentication within client code but not in server code, allowing server-side authentication to be bypassed via a modified client that omits the authentication check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an Ebyte device that uses client-managed authentication tokens without proper server-side validation. Attackers can replay or alter these tokens to gain unauthorized access to administrative functions.

Detection Guidance

This vulnerability involves replay or manipulation of authentication tokens in Ebyte devices. Detection requires monitoring network traffic for unusual token usage or unauthorized administrative access attempts. Check device logs for repeated authentication failures or unexpected token generation. Use packet capture tools like tcpdump or Wireshark to inspect token exchanges between clients and the device.

Impact Analysis

An attacker could exploit this to bypass authentication and gain control over the device's administrative features, potentially leading to data breaches, unauthorized system changes, or disruption of services.

Compliance Impact

This vulnerability could lead to unauthorized access, violating data protection requirements under GDPR and HIPAA. Non-compliance may result in legal penalties, fines, or reputational damage due to compromised sensitive data.

Mitigation Strategies

Implement server-side validation for authentication tokens to prevent replay or manipulation. Ensure tokens are unique, time-limited, and validated on the server side. Review and restrict administrative access to only trusted sources.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76945. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart