PT-2026-27112 · Nexxt Solutions · Nebula 300+ / Tenda F3 V2.0 Firmware
Angel Barre
·
Published
2026-03-23
·
Updated
2026-03-23
·
CVE-2026-31846
CVSS v2.0
6.1
Medium
| AV:A/AC:L/Au:N/C:C/I:N/A:N |
An unauthenticated credential disclosure vulnerability in the /goform/ate endpoint of Nexxt Solutions Nebula 300+ firmware through Nebula300+ v12.01.01.37 allows an adjacent attacker to obtain the administrator password in Base64-encoded form via a crafted HTTP request. The recovered credential can be used to authenticate to the device and facilitates further compromise when combined with other weaknesses present in the firmware.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nebula 300+ / Tenda F3 V2.0 Firmware