{"id":"CVE-2026-75814","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-75814","summary":"The Ebyte device does not adequately verify the origin or authenticity of \nrequests submitted to the web management interface. An unauthenticated \nremote attacker could persuade an…","details":"The Ebyte device does not adequately verify the origin or authenticity of \nrequests submitted to the web management interface. An unauthenticated \nremote attacker could persuade an authenticated administrator to visit a\n crafted page, causing unauthorized configuration changes or a \ndisruption of device availability.","published":"2026-08-28T00:18:14.147","modified":"2026-08-28T16:18:25.627","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json"},{"type":"WEB","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T16:18:25.627"}}