Cyber Resilience
← All news
Confirmed

Ebyte NA111-M

Our takeCISA advisory on the Ebyte NA111-M serial-to-Ethernet gateway: a dozen-plus CVEs in firmware 9013-2-17, adding up to full device compromise. These boxes get installed once and forgotten. Find yours, get it off the public internet, and ask Ebyte for fixed firmware.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of 12 vulnerabilities in Ebyte NA111-M Firmware 9013-2-17 that allow full device compromise. Review your OT/ICS inventory for this hardware and apply the vendor mitigations immediately.
What this means for you — Lean IT orgs:If you use Ebyte NA111-M industrial devices, they can be fully taken over right now. Check your equipment and update or isolate them as soon as possible.
What this means for you — MSP:CISA reports active exploitation in Ebyte NA111-M (firmware 9013-2-17). Scan client OT/ICS environments for this device; prioritize patching or network isolation where present.
What this means for you — Researcher:CISA reports active exploitation of multiple vulnerabilities (CVE-2026-73125 and others) in Ebyte NA111-M Firmware 9013-2-17 that lead to full device compromise.