CVE-2026-31846 - CERT CVE
ID CVE-2026-31846
Sažetak Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthenticated attacker to retrieve sensitive device information, including the administrator password. The endpoint returns a raw response containing parameters such as Login_PW, which is Base64-encoded. An attacker can decode this value to obtain valid administrative credentials and authenticate to the device.
Reference
CVSS
Base: 6.1
Impact: 6.9
Exploitability:6.5
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE NONE NONE
CVSS vektor AV:A/AC:L/Au:N/C:C/I:N/A:N
Zadnje važnije ažuriranje 26-03-2026 - 11:16
Objavljeno 23-03-2026 - 12:16