CVE-2026-77977
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
28/08/2026
Last modified:
28/08/2026
Description
Ebyte gateway product&#39;s vendor configuration utility does not require authentication before <br />
allowing certain disruptive administrative actions when default <br />
credentials remain configured. An unauthenticated attacker on the <br />
adjacent network could reboot the device or restore factory settings, <br />
resulting in a loss of configuration and service availability.
Impact
Base Score 4.0
7.20
Severity 4.0
HIGH
Base Score 3.x
8.10
Severity 3.x
HIGH



