Cyber Resilience
← All news
Confirmed

Ebyte NA111-M

Our takeCISA advisory on the Ebyte NA111-M serial-to-Ethernet gateway: a dozen-plus CVEs in firmware 9013-2-17, adding up to full device compromise. These boxes get installed once and forgotten. Find yours, get it off the public internet, and ask Ebyte for fixed firmware.
Sources (1)
What this means for you — Security leader:CISA advisory lists a dozen CVEs in Ebyte NA111-M firmware 9013-2-17 that let an attacker fully compromise the device. Locate any in your OT/ICS environment, isolate them from the internet, and request fixed firmware from Ebyte.
What this means for you — Lean IT orgs:These serial-to-Ethernet gateways are often installed once and then ignored. Check if you have any, unplug them from the public internet immediately, and contact Ebyte for updated firmware.
What this means for you — MSP:Scan client environments for Ebyte NA111-M devices running firmware 9013-2-17. Advise immediate internet isolation and firmware replacement per the CISA advisory.
What this means for you — Researcher:CISA advisory ICSA-26-239-05 details 12 CVEs in Ebyte NA111-M firmware 9013-2-17 enabling full device compromise. Review the CSAF for exploit paths and affected version confirmation.