CVE-2026-77975
Deferred Deferred - Pending Action

Ebyte Product Credential Exposure Vulnerability

Vulnerability report for CVE-2026-77975, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-09-01

Assigner: ICS-CERT

Description

The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use them to access the device or similarly configured systems.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-09-01
Generated
2026-09-21
AI Q&A
2026-08-31
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ebyte gateway From CSAFPID-0001 (inc)
ebyte gateway CSAFPID-0001

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the Ebyte product exporting administrative credentials and sensitive configuration details without proper protection. An attacker on the same network can access these exported files and recover valid credentials to gain unauthorized access to the device or other systems using the same configuration.

Detection Guidance

Detecting this vulnerability requires checking for exposed configuration files containing sensitive credentials. Monitor network traffic for unencrypted exports of device configurations. Inspect device logs for unusual access patterns or unauthorized configuration downloads.

Impact Analysis

An attacker could exploit this to gain control over the affected device or other systems using the same credentials. This may lead to data breaches, unauthorized modifications, or disruption of services.

Compliance Impact

This vulnerability could lead to unauthorized access and data exposure, violating confidentiality requirements in GDPR and HIPAA. Organizations may face legal penalties, reputational damage, and loss of compliance certifications.

Mitigation Strategies

Immediately disable or restrict access to configuration export features on affected devices. Change all administrative credentials that may have been exposed. Ensure configuration files are encrypted during transfer and stored securely.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77975. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart