CVE-2026-31847
Hidden Functionality Enables Remote Telnet Activation via /goform/setSysTools in Nexxt Nebula 300+
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
3th
Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters such as telnetManageEn=true and telnetPwd, an authenticated attacker can activate a Telnet service on port 23. This exposes a privileged diagnostic interface that is not intended for external access and can be used to interact with the underlying system.
| CWE | CWE-912 |
| Vendor | nexxt solutions |
| Product | nebula 300+ |
| Published | Mar 23, 2026 |
| Last Updated | Mar 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for nexxt solutions nebula 300+
Be the first to know when new unknown vulnerabilities affecting nexxt solutions nebula 300+ are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Nexxt Solutions / Nebula 300+
<= 12.01.01.37 โค Nebula300+_v12.01.01.37
References
Credits
Angel Barre (call4pwn)