Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing endpoints such as /goform/setSysTools and other administrative interfaces. As a result, an attacker can craft malicious web requests that are executed in the context of an authenticated administrator’s browser, leading to unauthorized configuration changes, including enabling services or modifying system settings.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing administrative endpoints. A remote attacker can induce an authenticated administrator to submit crafted requests that modify device settings, including security-relevant configuration, without the administrator's intent. | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing endpoints such as /goform/setSysTools and other administrative interfaces. As a result, an attacker can craft malicious web requests that are executed in the context of an authenticated administrator’s browser, leading to unauthorized configuration changes, including enabling services or modifying system settings. |
| Title | Missing CSRF protection on state-changing endpoints in Nexxt Nebula 300+ | Missing CSRF Protection on Administrative Endpoints in Nexxt Nebula 300+ |
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nexxtsolutions
Nexxtsolutions nebula300+ |
|
| Vendors & Products |
Nexxtsolutions
Nexxtsolutions nebula300+ |
Mon, 23 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing administrative endpoints. A remote attacker can induce an authenticated administrator to submit crafted requests that modify device settings, including security-relevant configuration, without the administrator's intent. | |
| Title | Missing CSRF protection on state-changing endpoints in Nexxt Nebula 300+ | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-03-26T10:45:40.996Z
Reserved: 2026-03-09T18:20:23.399Z
Link: CVE-2026-31849
Updated: 2026-03-23T15:17:49.181Z
Status : Awaiting Analysis
Published: 2026-03-23T13:16:30.640
Modified: 2026-03-26T11:16:20.827
Link: CVE-2026-31849
No data.
OpenCVE Enrichment
Updated: 2026-03-26T13:55:18Z