← back
CVE-2026-31850

Plaintext Storage of Credentials in Configuration Backup in Nexxt Nebula 300+

CVSS 6.8 MEDIUMEPSS 0.2%CWE-256
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.8EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
23 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative credentials and WiFi pre-shared keys, in plaintext within exported configuration backup files. These backup files can be obtained through legitimate functionality or other weaknesses and do not apply encryption or hashing, allowing attackers to directly extract sensitive information.
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →