ON August 25, 2026, CISA disclosed 11 vulnerabilities in the Ebyte NE2-D11 industrial IoT gateway, four of which are critically rated with a CVSS score of 9.8. These vulnerabilities allow attackers to gain full control over the device without needing authentication. The NE2-D11 is widely used in critical manufacturing and energy sectors worldwide. Currently, a patch is under development but not yet available. Users are advised to keep the gateways off the public internet, utilize firewalls, and implement VPNs for remote access to mitigate risks.
CISA warns of critical flaws in Ebyte NE2 D11 industrial gateways
CyberSIXT Evidence Panel
Primary Source
cisa.gov
Article by CyberSIXT