Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-76179

Gravedad CVSS v4.0:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
28/08/2026
Última modificación:
28/08/2026

Descripción

*** Pendiente de traducción *** An improper protection of authentication tokens vulnerability exists in <br /> certain Ebyte gateway products. Authentication tokens used by the web <br /> management interface are insufficiently protected during client-side <br /> session handling, which may allow an attacker with access to exposed <br /> session information to obtain and reuse a valid token. Successful <br /> exploitation could allow an attacker to impersonate an authenticated <br /> user and gain unauthorized access to device management functionality.