CVE-2026-77977
Deferred Deferred - Pending Action

Unauthenticated Reboot and Factory Reset in Ebyte Gateway Utility

Vulnerability report for CVE-2026-77977, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-31

Assigner: ICS-CERT

Description

Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on the adjacent network could reboot the device or restore factory settings, resulting in a loss of configuration and service availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-31
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ebyte gateway_product From CSAFPID-0001 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Ebyte gateway products. The vendor configuration utility allows disruptive administrative actions without authentication when default credentials are still set. An attacker on the same network can reboot the device or restore factory settings without needing to log in.

Detection Guidance

To detect this vulnerability, check if the Ebyte gateway product's vendor configuration utility allows unauthenticated administrative actions. Monitor network traffic for unauthorized reboot or factory reset commands. Inspect device logs for suspicious administrative actions without prior authentication.

Impact Analysis

If exploited, this flaw could cause loss of device configuration and service availability. The device may become unresponsive or require full reconfiguration, leading to downtime for connected systems.

Compliance Impact

This vulnerability could lead to unauthorized access or disruption of device operations, potentially causing data breaches or loss of service. For GDPR, this may result in unauthorized processing or loss of personal data, violating integrity and confidentiality principles. For HIPAA, it could expose protected health information if the device handles such data, leading to compliance failures under security and integrity rules.

Mitigation Strategies

Change default credentials on the Ebyte gateway product's vendor configuration utility to strong, unique passwords. Ensure the device is not accessible from adjacent networks without proper authentication. Regularly monitor device configurations for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77977. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart