THE Cybersecurity and Infrastructure Security Agency has issued an advisory on several vulnerabilities in Ebyte NA111-M devices, allowing remote attackers to bypass authentication and execute unauthorized commands. There are 9 identified CVEs, categorized as 4 critical, 4 high, and 1 medium. The highest severity score is 9.8 (CVE-2026-73125). Although there are no confirmed exploitations, these vulnerabilities pose significant risks to industrial networks globally.
Mitigations include isolating affected devices and implementing defensive network measures until a patch is available. Ebyte is reportedly developing a fix but has not yet provided updates.