CVE-2026-31849
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Mar 23, 2026
Vendor
unknown
Description
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing administrative endpoints. A remote attacker can induce an authenticated administrator to submit crafted requests that modify device settings, including security-relevant configuration, without the administrator's intent.