CVE-2026-31849

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing endpoints such as /goform/setSysTools and other administrative interfaces. As a result, an attacker can craft malicious web requests that are executed in the context of an authenticated administrator’s browser, leading to unauthorized configuration changes, including enabling services or modifying system settings.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nexxtsolutions:nebula300plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexxtsolutions:nebula300plus:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-23 13:16

Updated : 2026-06-17 10:34


NVD link : CVE-2026-31849

Mitre link : CVE-2026-31849

CVE.ORG link : CVE-2026-31849


JSON object : View

Products Affected

nexxtsolutions

  • nebula300plus_firmware
  • nebula300plus
CWE
CWE-352

Cross-Site Request Forgery (CSRF)