Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nexxtsolutions nebula300plus
Nexxtsolutions nebula300plus Firmware |
|
| CPEs | cpe:2.3:h:nexxtsolutions:nebula300plus:-:*:*:*:*:*:*:* cpe:2.3:o:nexxtsolutions:nebula300plus_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Nexxtsolutions nebula300plus
Nexxtsolutions nebula300plus Firmware |
|
| Metrics |
cvssV3_1
|
Thu, 26 Mar 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout on the authentication interface. | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction. |
| Title | Lack of rate limiting allows brute-force attacks in Nexxt Nebula 300+ | Lack of Rate Limiting Enables Brute-Force Attacks in Nexxt Nebula 300+ |
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nexxtsolutions
Nexxtsolutions nebula300+ |
|
| Vendors & Products |
Nexxtsolutions
Nexxtsolutions nebula300+ |
Mon, 23 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout on the authentication interface. | |
| Title | Lack of rate limiting allows brute-force attacks in Nexxt Nebula 300+ | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TuranSec
Published: 2026-03-23T12:21:54.907Z
Updated: 2026-03-26T10:47:04.841Z
Reserved: 2026-03-09T18:20:23.399Z
Link: CVE-2026-31851
Updated: 2026-03-23T15:16:33.710Z
Status : Analyzed
Published: 2026-03-23T13:16:30.960
Modified: 2026-04-29T17:37:36.430
Link: CVE-2026-31851
No data.