Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout on the authentication interface. | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction. |
| Title | Lack of rate limiting allows brute-force attacks in Nexxt Nebula 300+ | Lack of Rate Limiting Enables Brute-Force Attacks in Nexxt Nebula 300+ |
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nexxtsolutions
Nexxtsolutions nebula300+ |
|
| Vendors & Products |
Nexxtsolutions
Nexxtsolutions nebula300+ |
Mon, 23 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout on the authentication interface. | |
| Title | Lack of rate limiting allows brute-force attacks in Nexxt Nebula 300+ | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-03-26T10:47:04.841Z
Reserved: 2026-03-09T18:20:23.399Z
Link: CVE-2026-31851
Updated: 2026-03-23T15:16:33.710Z
Status : Awaiting Analysis
Published: 2026-03-23T13:16:30.960
Modified: 2026-03-26T11:16:21.117
Link: CVE-2026-31851
No data.
OpenCVE Enrichment
Updated: 2026-03-26T13:55:16Z