{"id":"CVE-2026-76940","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-76940","summary":"The affected Ebyte device does not restrict repeated authentication \nattempts through rate limiting or account lockout mechanisms. This could\n allow an attacker to perform automated…","details":"The affected Ebyte device does not restrict repeated authentication \nattempts through rate limiting or account lockout mechanisms. This could\n allow an attacker to perform automated authentication attacks against \ndeployments that rely on password based authentication.","published":"2026-08-28T00:18:15.190","modified":"2026-08-28T00:18:15.190","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json"},{"type":"WEB","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T00:18:15.190"}}