Nexxt Solutions Nebula 300+ CSRF Vulnerability in Administrative Endpoints

Vulnerability

A vulnerability exists in Nexxt Solutions Nebula 300+ routers running firmware through version 12.01.01.37, where cross-site request forgery (CSRF) protections are not applied to state-changing administrative endpoints. This flaw allows remote attackers to trick authenticated administrators into sending modified requests that change device settings, including important security configurations, without the administrators' knowledge.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in device settings, potentially allowing attackers to manipulate security-related configurations.

Added: Mar 23, 2026, 1:25 PM
Updated: Mar 23, 2026, 1:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.2
remediation
0.0
relevance
4.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.