Showing posts with label Ebyte. Show all posts
Showing posts with label Ebyte. Show all posts

Thursday, August 27, 2026

Review – 5 Advisories and 2 Updates Published – 8-27-26

 Today CISA’s NCCIC-ICS published five control system security advisories for products from Ebyte, Applied Systems Engineering, Rockwell Automation, All-Line Equipment, and Xiiaozet. They also updated two advisories for products from Mitsubishi. 

Advisories  

Ebyte Advisory - This advisory describes 13 vulnerabilities in the Ebyte NA111-M serial port server. The vulnerabilities were reported to CISA by Jithin Nambiar. 

Applied Systems Advisory - This advisory describes two vulnerabilities in the Applied Systems Engineering ASE2000 V2 Communications Test Set. The vulnerabilities were reported to CISA by Enoch Wang. 

Rockwell Advisory - This advisory describes a use of password hash with insufficient computational effort vulnerability in the Rockwell OTTO Fleet Manager. The vulnerability was self-reported. 

All-Line Equipment Advisory - This advisory discusses two vulnerabilities (both with public exploits) in the All-Line Fuel-Boss. These vulnerabilities were reported to CISA anonymously. 

Xiiaozet Advisory - This advisory describes three vulnerabilities in the Xiiaozet LK100W wireless print server. The vulnerabilities were reported to CISA by Byron Guernsey of Okachobi, LLC. 

Updates  

Mitsubishi Update #1 - This update provides additional information on the CNC Series advisory that was originally published on March 19th, 2026. 

Mitsubishi Update #2 - This update provides additional information on the Multiple FA Products advisory that was originally published on April 25th, 2025, and most recently updated on April 30th, 2026. 


For more information on these advisories, including a DTRH look at 3rd party exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-2-updates-published-b0d - subscription required. 

Tuesday, August 25, 2026

Review – 7 Advisories and 2 Updates Published – 8-25-26

Today CISA’s NCCIC-ICS published 7 control system security advisories for products from Furuno, Ebyte, Bendix, PayRange, Siemens, Zoneminder, and Rently. They also updated advisories for products from Lantronix and Optigo. 

Advisories  

Furuno Advisory - This advisory describes two vulnerabilities in the FURUNO FA-50 Class B AIS Transponder. The vulnerabilities were reported to CISA by Souvik Kandar. 

Ebyte Advisory - This advisory describes 11 vulnerabilities in the Ebyte NE2-D11 Firmware FW-9167-0-11. The vulnerability was reported to CISA by Jithin Nambiar. 

Bendix Advisory - This advisory describes three vulnerabilities in the Bendix EC80 Brake ECU. The vulnerabilities were reported to CISA by Ben Gardiner of NMFTA. 

PayRange Advisory - This advisory describes a missing authorization vulnerability in the PayRange API. The vulnerability was reported to CISA by Tahi Wilton Geary. 

Siemens Advisory - This advisory describes a missing authentication for critical function vulnerability in the Siemens SIMATIC IoT2050 Advanced. The vulnerability was self-reported. 

Zoneminder Advisory - This advisory describes an OS command injection vulnerability in the Zoneminder video surveillance system. Scriptkittens published an exploit for this vulnerability.  

Rently Advisory - This advisory describes an insufficiently protected credentials vulnerability in the Rently Smart Home. The vulnerability was reported to CISA by Berk Dusunur. 

Updates  

Lantronix Update - This update provides additional information on the Lantronix EDS3000PS advisory that was originally published on March 10th, 2026. 

Optigo Update - This update provides additional information on the Visual BACnet Capture Tool advisory that was originally published on March 11th, 2025. 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-2-updates-published-054 - subscription required. 

 
/* Use this with templates/template-twocol.html */