โ† Back to all CVEs

CVE-2026-31848

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Mar 23, 2026
Vendor unknown

Description

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores administrative authentication material in the ecos_pw cookie using a reversible Base64-encoded format with a static suffix. An attacker who obtains or derives this cookie value can forge a valid administrative session and gain unauthorized access to the device.

References