Security1 distinct publisher3 min readPublished
CISA says Ebyte confirmed the bug reports and said a fix was in development, then went quiet. Owners of the NE2-D11 gateway now have to plan around firmware that may never be replaced.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Read the five entries together and they describe one device rather than five separate mistakes. The web management interface makes authentication decisions in the browser, and CISA says that logic can be reproduced by an unauthenticated user well enough to generate valid authentication requests [3]. Where the browser is not even consulted, administrative functionality is reachable without authentication at all [2]. An attacker who would rather borrow a session than forge one can do that too: tokens are insufficiently protected during client-side session handling and can be obtained and reused to impersonate an authenticated user [6], and the traffic carrying them is not protected by transport encryption [4]. Administrative credentials may also sit in plaintext inside the interface itself [5].
Three of the five paths end in administrative access with no valid credential, and the other two hand over the credential or session material [13]. Both halves of an intrusion are described in the same document, against the same firmware build [1]. Nothing needs to be chained across vendors.
The part that changes how this is handled is the remediation block, which is identical under every entry. Ebyte acknowledged receipt, said a patch was under development, then stopped responding to coordination requests, and CISA says it has not been told whether that patch exists or is available [9]. The advice to users is to contact Ebyte [10]. In the field where a fixed version number belongs, there is a phone number the coordinator could not get answered [12].
That is not a delay an asset owner can schedule around. "Under development" is not a state anyone outside the vendor can verify, and no release date, build string, or advisory update is pending [9]. The devices are deployed worldwide in critical manufacturing and energy, and the company is headquartered in China [8], so the population of owners now individually chasing a vendor that has already gone silent on CISA is large, dispersed, and mostly unaware it is in the queue.
What remains are the controls that do not depend on the device believing anything. The gateway's own authentication cannot be relied on, so reachability becomes the control surface: which segment can open the web interface, and whether management traffic ever crosses a path where another host can read it [4]. Detection is harder to place, because a replayed token presents as a legitimate administrator [6], and the impacts CISA lists, configuration modification and disruption of device operation among them [7], are what an administrator is supposed to be able to do.
The honest planning assumption is that FW-9167-0-11 is the last firmware this device will ever run [1], and that its replacement is a procurement line rather than a patch ticket.
Ranked by verification strength, evidence, and original report placement.
CISA lists Ebyte NE2-D11 firmware FW-9167-0-11 as the known affected version for all reported vulnerabilities.
The Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality; an unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability (CWE-306, Missing Authentication for Critical Function).
The device relies on client-side authentication logic that can be reproduced by unauthenticated users, who may generate valid authentication requests and bypass authentication to obtain administrative access (CWE-603, Use of Client-Side Authentication).
The web management interface does not adequately protect sensitive communications with transport-layer encryption, so an attacker with access to network traffic could intercept authentication or session-related information (CWE-319, Cleartext Transmission of Sensitive Information).
Administrative credentials may be exposed in plaintext within the device's management interface, increasing the risk of credential compromise through visual or remote observation (CWE-522, Insufficiently Protected Credentials).
Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token and impersonate an authenticated user.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary-source advisory, thin on severity metrics
All substantive claims trace directly to a first-party CISA ICS advisory that names the affected firmware build, describes each weakness with a CWE mapping, and states the coordination outcome in CISA's own words. Evidence quality is high for existence and remediation status. It is capped short of the top band because the supplied text carries empty 'Metrics' sections with no CVE identifiers or CVSS scores, offers no reporter attribution, is truncated mid-entry, and has no second publisher corroborating any element.
Qualitative exposure only, no counts
The only exposure evidence is the advisory's own Background section: worldwide deployment across critical manufacturing and energy. That establishes the device is fielded in consequential environments but quantifies nothing - no install base, no internet-reachable device counts, no customer names, and no statement that exploitation has been observed. Scored low to reflect confirmed-but-unquantified real-world footprint rather than absent evidence.
Aligned, scope mildly understated
The cluster's headline framing - no fixed version because the vendor stopped answering - is exactly what the advisory says, and the impact language is quoted rather than escalated. The slight negative reflects understatement rather than overstatement: the derived five-entry count omits the cross-site request forgery and authentication rate-limiting entries that also appear in the supplied text, so the described attack surface is narrower than the source's.
Government disclosure duty, silent vendor
The single source is a government coordination body publishing under a disclosure mandate with no product to sell, which limits promotional distortion; the advisory even documents its own coordination failure, an admission against interest. Residual incentive pressure comes from the absence of any vendor statement or rebuttal in the cluster, so the affected party's side of the patch-status question is unrepresented.
Solid on facts, single-source on scope
High confidence that the vulnerabilities, affected firmware build and vendor non-response are as described, because they come from the issuing authority verbatim. Lower confidence on magnitude: no severity scores or CVE IDs in the supplied text, no exploitation status, no deployment counts, one publisher, and a truncated body that already contradicts the cluster's five-finding framing.
security
Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions1 distinct publisher
security
Siemens IoT2050 gateways ship a Node-RED interface that asks nobody for a password1 distinct publisher
product
The UK plant that went dark for four days was too small to have to tell anyone1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026