CVE Database
/

CVE-2026-31848

Back to search

CVE-2026-31848

Published: Mar 23, 2026

Modified: Mar 26, 2026

PUBLISHED

Description

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible and lacks integrity protection, an attacker can reconstruct or forge a valid cookie value without proper authentication. This allows unauthorized administrative access to protected endpoints.

VendorProductVersions

Nexxt Solutions

Nebula 300+

affected
<= 12.01.01.37

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now