← Vulnerability feed

Vulnerability record · CVE-2026-31847 · published 23 March 2026

CVE-2026-31847: Nexxtsolutions nebula300plus firmware vulnerability

NNexxtsolutions · Nebula300plus Firmware

Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters such as telnetManageEn=true and telnetPwd, an authenticated attacker can activate a Telnet service on port 23.

8.5 CVSS 4.0 High EPSS 0.68% · top 49.5% CWE-912 · CWE-912
8.5CVSS 4.0 base score
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
10 Aug 2026Last modified by NVD

Description

Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters such as telnetManageEn=true and telnetPwd, an authenticated attacker can activate a Telnet service on port 23.

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-31847 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-31848Nexxtsolutions nebula300plus firmware cleartext storage of sensitive data vulnerabilityNexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential…EPSS 0.46%7.7CVE-2026-31851Nexxtsolutions nebula300plus firmware improper restriction of authentication attempts vulnerabilityNexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication int…EPSS 0.67%7.2CVE-2026-31849Nexxtsolutions nebula300plus firmware cross-site request forgery vulnerabilityNexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing endpoints such as /goform/setS…EPSS 0.17%6.8CVE-2026-31850Nexxtsolutions nebula300plus firmware vulnerabilityNexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative credentials and WiFi pre-shar…EPSS 0.27%4.9CVE-2025-47729TeleMessage archiving backend stores cleartext message copiesThe TeleMessage archiving backend through 2025-05-05 retains cleartext copies of messages from TM SGNL (Archive Signal) app users, contradicting the …KEVEPSS 0.43%analysed9.8CVE-2024-20439Cisco Smart Licensing Utility hard-coded admin credential allows remote loginCisco Smart Licensing Utility (CSLU) contains an undocumented static credential for an administrative account. An unauthenticated remote attacker who…KEVEPSS 97%analysed6.7CVE-2021-25371Samsung Android DSP driver allows loading arbitrary ELF librariesThe DSP driver in Samsung Android devices before SMR Mar-2021 Release 1 permits loading of arbitrary ELF libraries inside the DSP. This breaks the in…KEVEPSS 0.80%analysed

Source: NIST National Vulnerability Database (record CVE-2026-31847), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.