PT-2026-27114 · Nexxt Solutions · Nebula 300+
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nexxt Solutions Nebula 300+ versions prior to 12.01.01.38
Description
Hidden functionality in the '/goform/setSysTools' endpoint allows an authenticated attacker to remotely enable a Telnet service on port 23. This is achieved by sending a crafted POST request using the
telnetManageEn and telnetPwd parameters. Once activated, the service exposes a privileged diagnostic management interface over the network, increasing the attack surface and potentially leading to further device compromise.Recommendations
Update Nexxt Solutions Nebula 300+ to a version newer than 12.01.01.37.
Restrict access to the '/goform/setSysTools' endpoint to minimize the risk of unauthorized service enablement.
Fix
Hidden Functionality
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nebula 300+