The Ebyte device relies on client side authentication logic that can be
reproduced by unauthenticated users. An attacker may generate valid
authentication requests and bypass authentication to obtain
administrative access to the device.
Ebyte acknowledged receipt of the reported vulnerabilities and indicated
that a patch was under development. However, the vendor has not
responded to subsequent requests for coordination, and CISA has not been
informed of the status or availability of the patch. Users are
encouraged to reach out to Ebyte for more information.