CISA published an ICS advisory for the Ebyte NA111-M industrial device, disclosing 13 vulnerabilities in firmware version 9013-2-17. Several relate directly to identity and access control weaknesses, including Missing Authentication for Critical Functions, Missing Authorization, Weak Authentication, Use of Client-Side Authentication, and Improper Restriction of Excessive Authentication Attempts (enabling brute-force). The advisory also cites cleartext transmission and storage of sensitive information, use of broken cryptographic algorithms, and CSRF — with a top CVSS v3 score of 9.8.
Collectively these flaws could allow an attacker to bypass authentication entirely and fully compromise the device’s web management interface, exposing credentials and administrative control. Because the device is deployed worldwide in Information Technology critical infrastructure sectors, compromised devices could serve as footholds for lateral movement and credential harvesting.
What to take away: authentication-bypass and weak-auth issues on network-facing management interfaces are a classic entry point for attackers seeking to pivot into broader identity infrastructure. Operators should restrict management access, apply vendor mitigations, and monitor for unauthorized authentication attempts.