CVE-2026-31849 Details
Description
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing endpoints such as /goform/setSysTools and other administrative interfaces. As a result, an attacker can craft malicious web requests that are executed in the context of an authenticated administrator’s browser, leading to unauthorized configuration changes, including enabling services or modifying system settings.
A vulnerability exists in Nexxt Solutions Nebula 300+ routers running firmware through version 12.01.01.37, where cross-site request forgery (CSRF) protections are not applied to state-changing administrative endpoints. This flaw allows remote attackers to trick authenticated administrators into sending modified requests that change device settings, including important security configurations, without the administrators' knowledge.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nexxt-connectivity-frontend.s3.amazonaws.com/media/docs/Nebula300+_v12.01.01.37.zip | TuranSec | Product |
| https://www.nexxtsolutions.com/connectivity/internal-products/ARN02304U6/ | TuranSec | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | TuranSec |
Affected Products
| Product | Versions |
|---|---|
| nexxtsolutions nebula300plus firmware | <= 12.01.01.37 |
CPE
Remediation
| |
| nexxtsolutions nebula300plus | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TuranSec |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | CVE Modified | TuranSec |
| Mar 23, 2026 | New CVE Received | TuranSec |