Nexxtsolutions develops a narrow line of wireless access points and network appliances such as the Nebula and AMP product families, which serve small-to-medium enterprise deployments. Its vulnerability profile skews strongly toward critical-severity outcomes and frequently acquires public exploit code, while the recurring weakness classes—cleartext credential storage, cross-site request forgery, hidden functionality, OS command injection, and improper brute-force protections—reflect typical embedded-device authentication and administrative-interface gaps. Defenders should prioritize patching these appliances, particularly when internet-reachable, and audit administrative access; live severity and exploit-availability figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nexxtsolutions over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44149HIGH The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature | Jan 6, 2023 | 8.8 | 75 | NO | YES |
CVE-2026-31851CRITICAL Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perfor | Mar 23, 2026 | 9.8 | 30 | NO | NO |
CVE-2022-46080CRITICAL Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET. | Jul 6, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-31848CRITICAL Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static su | Mar 23, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-31847HIGH Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sendin | Mar 23, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-31849MEDIUM Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing endpoints such as /goform/setSysTools and other administrativ | Mar 23, 2026 | 6.5 | 23 | NO | NO |
CVE-2026-31850MEDIUM Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative credentials and WiFi pre-shared keys, in plaintext within ex | Mar 23, 2026 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nexxtsolutions.
Media articles that mention a CVE ID that affects a product developed by Nexxtsolutions — matched by CVE ID, not by vendor name.