SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77977

HIGH · CVSS 8.1 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Ebyte gateway's vendor configuration utility is vulnerable due to a lack of authentication, allowing unauthenticated attackers on the same network to perform critical administrative actions, such as rebooting the device or restoring factory settings. This could lead to significant service disruptions and loss of configuration data. Organizations using Ebyte gateways should prioritize addressing this vulnerability to mitigate potential operational impacts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77977
Severity
HIGH
CVSS
8.1
EPSS
0.23%

Original NVD Description

Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on the adjacent network could reboot the device or restore factory settings, resulting in a loss of configuration and service availability.