Impact
The vulnerability involves hidden functionality in the /goform/setSysTools endpoint of Nexxt Solutions Nebula 300+ firmware up to version 12.01.01.37. An authenticated attacker can craft a POST request with parameters such as telnetManageEn=true and telnetPwd that activates a Telnet service on port 23. This exposes a privileged diagnostic interface not intended for public use, representing a CWE‑912 flaw that effectively enables remote code execution or privileged command execution for the attacker.
Affected Systems
This issue affects Nexxt Solutions Nebula 300+ devices running firmware versions 12.01.01.37 and earlier. The affected system is the Nebula 300+ network gateway, which typically serves as a local management point for connectivity infrastructure.
Risk and Exploitability
The vulnerability scores as CVSS 8.5, indicating high severity, while the EPSS score is below 1%, implying current exploit prevalence is low and the vulnerability is not on the CISA Known Exploited Vulnerabilities list. Attackers need valid credentials to reach the endpoint, so the exploit requires prior access or credential compromise, but once authenticated, the attacker can activate Telnet with a simple POST request. The applied risk is elevated when the Nebula device is exposed to untrusted networks, as the enabled Telnet service opens a channel for arbitrary command execution.
OpenCVE Enrichment