SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77975

MEDIUM · CVSS 6.5 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Ebyte product is vulnerable due to the insecure export of administrative credentials and sensitive configuration data, which can be accessed without authentication. An attacker on the adjacent network could exploit this flaw to retrieve the configuration file, potentially gaining unauthorized access to the device and similar systems. Organizations using affected Ebyte products should prioritize remediation to mitigate the risk of credential theft and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77975
Severity
MEDIUM
CVSS
6.5
EPSS
0.18%

Original NVD Description

The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use them to access the device or similarly configured systems.