PT-2026-27112 · Nexxt Solutions · Nebula 300+
Angel Barre
·
Published
2026-03-23
·
Updated
2026-03-23
·
CVE-2026-31846
CVSS v2.0
6.1
Medium
| Vector | AV:A/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nexxt Solutions Nebula 300+ firmware versions through 12.01.01.37
Description
A flaw exists that allows an unauthenticated attacker to retrieve sensitive device information, including the administrator password. The issue is present in the
/goform/ate API endpoint. A crafted HTTP request to this endpoint returns a response containing parameters such as Login PW, which is Base64-encoded. An attacker can decode this value to obtain valid administrative credentials and authenticate to the device. Successful exploitation allows an adjacent attacker to obtain the administrator password. The recovered credential can be used to authenticate to the device and may facilitate further compromise.Recommendations
Versions prior to 12.01.01.37 should be updated.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nebula 300+