SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-71187

CRITICAL · CVSS 9.8 EPSS 0.52% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability affects Ebyte devices that utilize flawed client-side authentication logic, allowing unauthenticated users to generate valid authentication requests. This critical flaw enables attackers to bypass authentication and gain administrative access, potentially compromising the device's security and functionality. Organizations using Ebyte products should prioritize remediation to prevent unauthorized access and potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-71187
Severity
CRITICAL
CVSS
9.8
EPSS
0.52%

Original NVD Description

The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.