CVE-2026-31846 - CERT CVE
ID CVE-2026-31846
Sažetak An unauthenticated credential disclosure vulnerability in the /goform/ate endpoint of Nexxt Solutions Nebula 300+ firmware through Nebula300+_v12.01.01.37 allows an adjacent attacker to obtain the administrator password in Base64-encoded form via a crafted HTTP request. The recovered credential can be used to authenticate to the device and facilitates further compromise when combined with other weaknesses present in the firmware.
Reference
CVSS
Base: 6.1
Impact: 6.9
Exploitability:6.5
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE NONE NONE
CVSS vektor AV:A/AC:L/Au:N/C:C/I:N/A:N
Zadnje važnije ažuriranje 23-03-2026 - 14:31
Objavljeno 23-03-2026 - 12:16