Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction.
References
Configurations
Configuration 1 (hide)
| AND |
|
History
29 Apr 2026, 17:37
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| First Time |
Nexxtsolutions nebula300plus Firmware
Nexxtsolutions Nexxtsolutions nebula300plus |
|
| References | () https://nexxt-connectivity-frontend.s3.amazonaws.com/media/docs/Nebula300+_v12.01.01.37.zip - Product | |
| References | () https://www.nexxtsolutions.com/connectivity/internal-products/ARN02304U6/ - Product | |
| CPE | cpe:2.3:o:nexxtsolutions:nebula300plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:nexxtsolutions:nebula300plus:-:*:*:*:*:*:*:* |
26 Mar 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| Summary | (en) Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction. |
23 Mar 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-23 13:16
Updated : 2026-04-29 17:37
NVD link : CVE-2026-31851
Mitre link : CVE-2026-31851
CVE.ORG link : CVE-2026-31851
JSON object : View
Products Affected
nexxtsolutions
- nebula300plus_firmware
- nebula300plus
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
