CVE-2026-31848 Details
Description
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible and lacks integrity protection, an attacker can reconstruct or forge a valid cookie value without proper authentication.
A vulnerability exists in Nexxt Solutions Nebula 300+ routers running firmware through version 12.01.01.37. The issue arises because administrative authentication data is stored in the ecos_pw cookie in a reversible Base64-encoded format, appended with a static suffix. This allows an attacker who retrieves or decodes the cookie value to create a valid administrative session, gaining unauthorized access to the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nexxt-connectivity-frontend.s3.amazonaws.com/media/docs/Nebula300+_v12.01.01.37.zip | TuranSec | Product |
| https://www.nexxtsolutions.com/connectivity/internal-products/ARN02304U6/ | TuranSec | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | TuranSec |
Affected Products
| Product | Versions |
|---|---|
| nexxtsolutions nebula300plus firmware | <= 12.01.01.37 |
CPE
Remediation
| |
| nexxtsolutions nebula300plus | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | CVE Modified | TuranSec |
| Jun 17, 2026 | CVE Modified | TuranSec |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | CVE Modified | TuranSec |
| Mar 23, 2026 | New CVE Received | TuranSec |