CVE-2026-77977

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
28/08/2026
Last modified:
28/08/2026

Description

Ebyte gateway product&amp;#39;s vendor configuration utility does not require authentication before <br /> allowing certain disruptive administrative actions when default <br /> credentials remain configured. An unauthenticated attacker on the <br /> adjacent network could reboot the device or restore factory settings, <br /> resulting in a loss of configuration and service availability.