CVE-2026-76179
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
28/08/2026
Last modified:
28/08/2026
Description
An improper protection of authentication tokens vulnerability exists in <br />
certain Ebyte gateway products. Authentication tokens used by the web <br />
management interface are insufficiently protected during client-side <br />
session handling, which may allow an attacker with access to exposed <br />
session information to obtain and reuse a valid token. Successful <br />
exploitation could allow an attacker to impersonate an authenticated <br />
user and gain unauthorized access to device management functionality.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL



