CVE-2026-31847
Nexxt Solutions Nebula 300+, nebula300plus firmware, nebula300plus
Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters such as telnetManageEn=true and telnetPwd, an authenticated attacker can activate a Telnet service on port 23.
- CVSS
- 8.5
- EPSS
- 0.42% 35.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.23