CVE-2026-31848 is a high-severity authentication bypass vulnerability in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37. The vulnerability exists in the ecos_pw cookie used for authentication, which contains Base64-encoded credential data combined with a static suffix. The encoding is reversible and lacks integrity protection, allowing an attacker to reconstruct or forge a valid cookie v [truncated]
The CVE-2026-31847 vulnerability affects Nexxt Solutions Nebula 300+ devices, specifically in the /goform/setSysTools endpoint, allowing remote enablement of a Telnet service. This vulnerability has a CVSS score of 8.5 and is classified as HIGH severity. System administrators and security teams should be aware of this vulnerability and take necessary actions to prevent potential exploitation. The CVE reco [truncated]
A missing authentication vulnerability in Nexxt Solutions Nebula 300+ wireless routers allows adjacent unauthenticated attackers to retrieve administrative credentials. The /goform/ate endpoint returns device configuration data including a Base64-encoded administrator password (Login_PW parameter) without requiring authentication. Successful exploitation grants full administrative access to the device. Th [truncated]