Ebyte NE2-D11 Gateway Hit by 11 Vulnerabilities, No Patch Yet
ID: 8ec2b996-4857-5c21-9d07-52bed680ecbb
STIX ID: report--8ec2b996-4857-5c21-9d07-52bed680ecbb
Feed Name: securityonline.info
**CISA disclosed 11 vulnerabilities in the Ebyte NE2-D11 industrial IoT gateway (FW-9167-0-11), four rated CVSS 9.8; flaws include weak or inconsistent authentication and cleartext MQTT credentials that could allow remote attackers to read or change configuration, hijack sessions, or seize full control.** No public exploitation or CVEs have been reported and no confirmed patch is available; CISA and the vendor have provided mitigation guidance such as removing gateways from the public internet, placing them behind firewalls, and using VPNs in line with ICS advisory ICSA-26-237-06.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
