The affected Ebyte
product does not provide separation between limited and administrative
management functions. A low privileged authenticated attacker could
access security sensitive configuration functions and modify settings
that affect the confidentiality, integrity, or availability of the
device.
Ebyte acknowledged receipt of the reported vulnerabilities and indicated
that a patch was under development. However, the vendor has not
responded to subsequent requests for coordination, and CISA has not been
informed of the status or availability of the patch. Users are
encouraged to reach out to Ebyte for more information.