Subscriptions
No data.
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 23 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated credential disclosure vulnerability in the /goform/ate endpoint of Nexxt Solutions Nebula 300+ firmware through Nebula300+_v12.01.01.37 allows an adjacent attacker to obtain the administrator password in Base64-encoded form via a crafted HTTP request. The recovered credential can be used to authenticate to the device and facilitates further compromise when combined with other weaknesses present in the firmware. | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-03-23T15:52:26.640Z
Reserved: 2026-03-09T18:20:23.399Z
Link: CVE-2026-31846
Updated: 2026-03-23T15:07:14.396Z
Status : Awaiting Analysis
Published: 2026-03-23T12:16:07.267
Modified: 2026-03-23T14:31:37.267
Link: CVE-2026-31846
No data.
OpenCVE Enrichment
No data.