CVE-2026-31851 Details
Description
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction.
A vulnerability exists in the Nexxt Solutions Nebula 300+ wireless router, specifically in firmware versions through 12.01.01.37. The issue arises because the authentication interface does not implement proper rate limiting or account lockout mechanisms. This oversight could potentially allow for brute force attacks or other forms of unauthorized access.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nexxt-connectivity-frontend.s3.amazonaws.com/media/docs/Nebula300+_v12.01.01.37.zip | TuranSec | Product |
| https://www.nexxtsolutions.com/connectivity/internal-products/ARN02304U6/ | TuranSec | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | TuranSec |
Affected Products
| Product | Versions |
|---|---|
| nexxtsolutions nebula300plus firmware | <= 12.01.01.37 |
CPE
Remediation
| |
| nexxtsolutions nebula300plus | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TuranSec |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | CVE Modified | TuranSec |
| Mar 23, 2026 | New CVE Received | TuranSec |