CVE-2026-31847

Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters such as telnetManageEn=true and telnetPwd, an authenticated attacker can activate a Telnet service on port 23.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nexxtsolutions:nebula300plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexxtsolutions:nebula300plus:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-23 13:16

Updated : 2026-08-10 12:17


NVD link : CVE-2026-31847

Mitre link : CVE-2026-31847

CVE.ORG link : CVE-2026-31847


JSON object : View

Products Affected

nexxtsolutions

  • nebula300plus_firmware
  • nebula300plus
CWE
CWE-912

Hidden Functionality