PT-2026-27112 · Nexxt Solutions · Nebula 300+

Angel Barre

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-31846

CVSS v2.0

6.1

Medium

VectorAV:A/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nexxt Solutions Nebula 300+ firmware versions through 12.01.01.37
Description A flaw exists that allows an unauthenticated attacker to retrieve sensitive device information, including the administrator password. The issue is present in the /goform/ate API endpoint. A crafted HTTP request to this endpoint returns a response containing parameters such as Login PW, which is Base64-encoded. An attacker can decode this value to obtain valid administrative credentials and authenticate to the device. Successful exploitation allows an adjacent attacker to obtain the administrator password. The recovered credential can be used to authenticate to the device and may facilitate further compromise.
Recommendations Versions prior to 12.01.01.37 should be updated.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-31846

Affected Products

Nebula 300+