๐Ÿ” CVE Alert

CVE-2026-31847

UNKNOWN 0.0

Hidden Functionality Enables Remote Telnet Activation via /goform/setSysTools in Nexxt Nebula 300+

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
3th

Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters such as telnetManageEn=true and telnetPwd, an authenticated attacker can activate a Telnet service on port 23. This exposes a privileged diagnostic interface that is not intended for external access and can be used to interact with the underlying system.

CWE CWE-912
Vendor nexxt solutions
Product nebula 300+
Published Mar 23, 2026
Last Updated Mar 26, 2026
Stay Ahead of the Next One

Get instant alerts for nexxt solutions nebula 300+

Be the first to know when new unknown vulnerabilities affecting nexxt solutions nebula 300+ are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Nexxt Solutions / Nebula 300+
<= 12.01.01.37 โ‰ค Nebula300+_v12.01.01.37

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
nexxtsolutions.com: https://www.nexxtsolutions.com/connectivity/internal-products/ARN02304U6/ nexxt-connectivity-frontend.s3.amazonaws.com: https://nexxt-connectivity-frontend.s3.amazonaws.com/media/docs/Nebula300+_v12.01.01.37.zip

Credits

Angel Barre (call4pwn)