216.73.216.6

CVE-2026-31847

· Published 23/03/2026 13:16 · Modified 23/03/2026 14:31

Labels: CVE-2026-31847 2026-03-23309f9ea4-e3e9-4c6c-b79d-e8eb01244f2cCVE-2026-31847CWE-912

Essential information

Published
23/03/2026 13:16
Modified
23/03/2026 14:31
Author
Creator
CVSS
8.5 HIGH (v3) 8.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. Once enabled, the service exposes a privileged diagnostic management interface over the network, increasing the attack surface and enabling further compromise of the device.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
NVD
View on NVD

Affected products (CPE)

ProductCPE
nexxt solutions / nebula 300+ cpe:2.3:a:nexxt_solutions:nebula_300+:*:12.01.01.37:*:*:*:*:*:*
nexxt solutions / nebula 300+ cpe:2.3:a:nexxt_solutions:nebula_300+:<12.01.01.37:*:*:*:*:*:*

References