# CVE-2026-31847

## Summary

- **CVE ID:** CVE-2026-31847
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-912
- **Published:** Mar 23, 2026
- **Last Modified:** Aug 10, 2026

## Description

Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. Once enabled, the service exposes a privileged diagnostic management interface over the network, increasing the attack surface and enabling further compromise of the device.

## Affected Products

- Nexxt Solutions — Nebula 300+ (<= 12.01.01.37)

## References

- [CNA](https://www.nexxtsolutions.com/connectivity/internal-products/ARN02304U6/)
- [CNA](https://nexxt-connectivity-frontend.s3.amazonaws.com/media/docs/Nebula300+_v12.01.01.37.zip)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.42%
- **EPSS Percentile:** 35.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._