---
id: CVE-2026-31846
title: >-
  Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula
  300+ firmware through version 12.01.01.37 allows an adjacent unauthenticated
  attacker to retrieve sensitive device information, including the administrator
  pass…
summary: >-
  Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula
  300+ firmware through version 12.01.01.37 allows an adjacent unauthenticated
  attacker to retrieve sensitive device information, including the administrator
  pass…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-306
published: '2026-03-23'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-31846'
references:
  - url: >-
      https://nexxt-connectivity-frontend.s3.amazonaws.com/media/docs/Nebula300+_v12.01.01.37.zip
    label: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
  - url: 'https://www.nexxtsolutions.com/connectivity/internal-products/ARN02304U6/'
    label: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
tags:
  - nvd
epss: 0.00393
epssPercentile: 0.30748
ingestedAt: '2026-08-10T12:39:46.271Z'
---

## Overview

Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthenticated attacker to retrieve sensitive device information, including the administrator password. An attacker can decode this value to obtain valid administrative credentials and authenticate to the device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
