Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. Once enabled, the service exposes a privileged diagnostic management interface over the network, increasing the attack surface and enabling further compromise of the device.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 23 Mar 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. Once enabled, the service exposes a privileged diagnostic management interface over the network, increasing the attack surface and enabling further compromise of the device. | |
| Title | Hidden functionality allows remote Telnet enablement in Nexxt Nebula 300+ | |
| Weaknesses | CWE-912 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-03-23T12:07:05.062Z
Reserved: 2026-03-09T18:20:23.399Z
Link: CVE-2026-31847
No data.
Status : Received
Published: 2026-03-23T13:16:30.320
Modified: 2026-03-23T13:16:30.320
Link: CVE-2026-31847
No data.
OpenCVE Enrichment
No data.
Weaknesses