CVE-2026-31849
Received
Received - Intake
CSRF Vulnerability in Nexxt Nebula 300+ Firmware Allows Unauthorized Settings Changes
Publication date: 2026-03-23
Last updated on: 2026-04-29
Assigner: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
Description
Description
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing endpoints such as /goform/setSysTools and other administrative interfaces. As a result, an attacker can craft malicious web requests that are executed in the context of an authenticated administratorβs browser, leading to unauthorized configuration changes, including enabling services or modifying system settings.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nexxtsolutions | nebula300plus_firmware | to 12.01.01.37 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-352 | The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor. |