Government Advisory

Critical Security Flaws Found in Ebyte NA111-M Industrial Device

CISA · 27 Aug 2026
Key Takeaway Check whether any connected devices or industrial equipment in your business use the Ebyte NA111-M, apply vendor patches promptly, and avoid exposing such devices directly to the internet.

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory warning of a large set of security vulnerabilities affecting the Ebyte NA111-M device running firmware version 9013-2-17. The flaws have been rated with a severity score of 9.8 out of 10, indicating a critical level of risk.

The vulnerabilities include weak or missing authentication, sensitive data being transmitted or stored without encryption, weak cryptography, and susceptibility to attacks such as cross-site request forgery. In combination, these issues could allow an attacker to bypass login protections, intercept sensitive information, or gain full control over the device without needing valid credentials.

While this device is more commonly used in industrial and operational technology environments, Australian small businesses that rely on connected hardware, remote monitoring equipment, or networked devices from any vendor should take note. Devices with weak authentication and unencrypted data handling are a common entry point for attackers targeting small business networks.

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.