CISA Warns of 13 Critical Flaws in Ebyte NA111-M Gateways, No Patch in Sight

The Chinese vendor stopped responding to coordination requests, leaving industrial network gateways exposed to remote takeover.

ThreatVectr Newsdesk· 3 min read
Full-frame 16:9 photoreal editorial shot of an electrical substation control cabinet at dusk, rows of protection relays with small status LEDs glowing amber and
Share

Key points

  • CISA disclosed 13 vulnerabilities in the Ebyte NA111-M gateway, firmware version 9013-2-17, with the worst rated 9.8 out of 10 on the industry severity scale.
  • The flaws allow a remote attacker to fully take over the device without a password.
  • Ebyte, headquartered in China, acknowledged the report but has since gone silent, and no patch has been released.
  • The devices are deployed worldwide in the information technology sector.
  • Owners have no fix available and are being told to contact the vendor directly.

A small industrial gateway sold worldwide by Chinese manufacturer Ebyte can be hijacked over the internet by anyone who knows where to look. There is no patch. The vendor has stopped replying.

The U.S. Cybersecurity and Infrastructure Security Agency, known as CISA, published an advisory this week detailing 13 separate security flaws in the Ebyte NA111-M, a network gateway used to connect industrial equipment to corporate networks. Every version running firmware 9013-2-17 is affected.

The headline problem is simple. The device's web management interface, the browser-based control panel an administrator uses to configure it, does not always check whether the person clicking is actually logged in. That flaw, tracked as CVE-2026-73125, scores 9.8 out of 10 for severity. An attacker anywhere on the internet can read settings, change them, or knock the device offline.

Twelve more issues sit alongside it. Some are as basic as sending passwords across the network in plain text, meaning anyone watching the traffic can grab them. Others let an attacker trick a logged-in administrator into making changes without realising it, a technique called cross-site request forgery. The device also has no lockout after repeated failed logins, so an attacker can guess passwords as fast as their computer will allow.

Who makes this device and where is it used?

Ebyte is a Chinese electronics manufacturer whose NA111-M is sold as an industrial serial-to-Ethernet gateway. CISA lists deployments as worldwide and places the device in the information technology sector. In practice, gateways like this sit quietly inside factories, utilities and building management systems, translating data between old serial equipment and modern networks.

Is there a patch?

No. CISA says Ebyte confirmed receipt of the vulnerability report and said a patch was being developed. Then the company stopped responding to follow-up messages. CISA has not been told when, or whether, a fix will ship. Owners of the device are being told to contact Ebyte directly.

That is an unusually blunt statement from a government advisory, and it puts operators in an awkward spot.

What should owners do now?

Assume the device should not be reachable from the public internet. Any NA111-M with its web interface exposed online should be pulled behind a firewall or VPN immediately. Network administrators should check logs for unexpected configuration changes and rotate any passwords that may have crossed the device in plain text.

Beyond that, there is little to do until Ebyte ships a firmware update.

Detail Value
Vendor Ebyte (China)
Product NA111-M gateway
Affected firmware 9013-2-17
Number of CVEs 13
Highest CVSS score 9.8 (critical)
Patch status None available

Why this matters beyond the device itself

Gateways are quiet targets. They rarely appear on an asset inventory, they sit at the edge of the network, and they often have credentials that let them talk to more valuable systems inside. A gateway an attacker fully controls is a foothold, not just a broken box.

The pattern here, a small vendor, a critical flaw, no fix, is one CISA has flagged repeatedly across industrial equipment this year. It puts the burden on the buyer to design networks that survive a vendor going quiet.

© 2026 Threat Vectr