CVE-2026-75814
Severity CVSS v4.0:
HIGH
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
28/08/2026
Last modified:
28/08/2026
Description
The Ebyte device does not adequately verify the origin or authenticity of <br />
requests submitted to the web management interface. An unauthenticated <br />
remote attacker could persuade an authenticated administrator to visit a<br />
crafted page, causing unauthorized configuration changes or a <br />
disruption of device availability.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH



