๐Ÿ” CVE Alert

CVE-2026-31848

UNKNOWN 0.0

Reversible ecos_pw Cookie Allows Authentication Bypass in Nexxt Nebula 300+

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
6th

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible and lacks integrity protection, an attacker can reconstruct or forge a valid cookie value without proper authentication. This allows unauthorized administrative access to protected endpoints.

CWE CWE-312
Vendor nexxt solutions
Product nebula 300+
Published Mar 23, 2026
Last Updated Mar 26, 2026
Stay Ahead of the Next One

Get instant alerts for nexxt solutions nebula 300+

Be the first to know when new unknown vulnerabilities affecting nexxt solutions nebula 300+ are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Nexxt Solutions / Nebula 300+
<= 12.01.01.37

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
nexxtsolutions.com: https://www.nexxtsolutions.com/connectivity/internal-products/ARN02304U6/ nexxt-connectivity-frontend.s3.amazonaws.com: https://nexxt-connectivity-frontend.s3.amazonaws.com/media/docs/Nebula300+_v12.01.01.37.zip

Credits

Angel Barre (call4pwn)