Critical Security Flaws Found in Ebyte NE2-D11 Industrial Devices
CISA has issued an advisory for the Ebyte NE2-D11, an industrial device used in sectors including critical manufacturing and energy, after identifying multiple serious security flaws in its firmware (version FW-9167-0-11). The vulnerabilities have received a near-maximum severity score of 9.8 out of 10, reflecting how easily they could be exploited and how much damage they could cause.
The issues include missing authentication controls, transmission of sensitive data without encryption, weak protection of login credentials, and susceptibility to session hijacking and cross-site request forgery attacks. In combination, these flaws could allow an attacker to gain administrative access to the device without proper credentials, view or steal sensitive information, alter device settings, or interfere with its normal operation.
While the Ebyte NE2-D11 is primarily used in industrial and operational technology environments, small and medium businesses that rely on connected industrial equipment or third-party vendors using this device should take note. Businesses should check with equipment suppliers or IT partners to confirm whether this device is in use within their operations and apply any vendor-issued updates or mitigations as soon as they become available.