Nexxtsolutions
nexxtsolutions
7 CVEs • 6 products
Products (6)
Click to collapseToggle
Products (6)
Click to collapse
CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Nexxtsolutions 1Nebula300plus Firmware Jun 17, 2026 Mar 23, 2026 7.7 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts agai...Show more |
1Nexxtsolutions 1Nebula300plus Firmware Jun 17, 2026 Mar 23, 2026 6.8 MEDIUM· v4 4.9 MEDIUM· v3 N/A· v2 Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative credentials and WiFi pre-shared keys, in plaintext within exported configuration backup files. These...Show more |
1Nexxtsolutions 1Nebula300plus Firmware Jun 17, 2026 Mar 23, 2026 7.2 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing endpoints such as /goform/setSysTools and other administrative interfaces. As a result, an attacker c...Show more |
1Nexxtsolutions 1Nebula300plus Firmware Jun 17, 2026 Mar 23, 2026 8.7 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible...Show more |
1Nexxtsolutions 1Nebula300plus Firmware Jun 17, 2026 Mar 23, 2026 8.5 HIGH· v4 8.8 HIGH· v3 N/A· v2 Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters...Show more |
1Nexxtsolutions 1Nebula1200 Ac Firmware Jun 17, 2026 Jul 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET. |
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authe...Show more |