CVE-2026-31848

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible and lacks integrity protection, an attacker can reconstruct or forge a valid cookie value without proper authentication.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nexxtsolutions:nebula300plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexxtsolutions:nebula300plus:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-23 13:16

Updated : 2026-08-10 12:17


NVD link : CVE-2026-31848

Mitre link : CVE-2026-31848

CVE.ORG link : CVE-2026-31848


JSON object : View

Products Affected

nexxtsolutions

  • nebula300plus_firmware
  • nebula300plus
CWE
CWE-312

Cleartext Storage of Sensitive Information