Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endpoint that reveals the current identifier high-water mark, the active fleet can be enumerated.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Naxclow did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Naxclow for more information.


Workaround

No workaround given by the vendor.

History

Fri, 12 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Description Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endpoint that reveals the current identifier high-water mark, the active fleet can be enumerated.
Title Naxclow IoT Platform Generation of Predictable Numbers or Identifiers
Weaknesses CWE-340
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-06-12T19:00:34.450Z

Reserved: 2026-06-08T20:04:55.544Z

Link: CVE-2026-42932

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-12T19:16:27.650

Modified: 2026-06-12T19:16:27.650

Link: CVE-2026-42932

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses