CVE-2026-31848

Publication date

2026-03-23 12:09:30

Family

TuranSec

State

PUBLISHED

Description

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores administrative authentication material in the ecos_pw cookie using a reversible Base64-encoded format with a static suffix. An attacker who obtains or derives this cookie value can forge a valid administrative session and gain unauthorized access to the device.