โ† Back to all CVEs

CVE-2026-31849

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Mar 23, 2026
Vendor unknown

Description

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing administrative endpoints. A remote attacker can induce an authenticated administrator to submit crafted requests that modify device settings, including security-relevant configuration, without the administrator's intent.

References