CVE-2026-31846 Details
Description
Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthenticated attacker to retrieve sensitive device information, including the administrator password. An attacker can decode this value to obtain valid administrative credentials and authenticate to the device.
A vulnerability allowing unauthenticated credential disclosure has been identified in the Nexxt Solutions Nebula 300+ wireless router, specifically in the firmware version Nebula300+_v12.01.01.37. This vulnerability resides in the /goform/ate endpoint, where an adjacent attacker can obtain the administrator password in Base64-encoded form by sending a crafted HTTP request. The extracted credential can be used to authenticate to the device, potentially leading to further compromise when combined with other existing weaknesses in the firmware.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 23, 2026CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nexxt-connectivity-frontend.s3.amazonaws.com/media/docs/Nebula300+_v12.01.01.37.zip | TuranSec | Broken Link |
| https://www.nexxtsolutions.com/connectivity/internal-products/ARN02304U6/ | TuranSec | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | TuranSec |
Affected Products
| Product | Versions |
|---|---|
| Nexxt Nebula 300+ | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | CVE Modified | TuranSec |
| Jun 17, 2026 | CVE Modified | TuranSec |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | CVE Modified | TuranSec |
| Mar 23, 2026 | New CVE Received | TuranSec |
Volerion