Project Subscriptions
No data.
No advisories yet.
Solution
Naxclow did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Naxclow for more information.
Workaround
No workaround given by the vendor.
Fri, 12 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequential device identifier and returns the current high-water counter value for the batch, allowing callers to measure and enumerate the active device space. The endpoint’s behavior enables precise fleet enumeration. | |
| Title | Naxclow IoT Platform Missing Authorization | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-06-12T19:00:11.857Z
Reserved: 2026-06-08T20:04:55.551Z
Link: CVE-2026-50244
Updated: 2026-06-12T19:00:08.573Z
Status : Received
Published: 2026-06-12T19:16:29.773
Modified: 2026-06-12T19:16:29.773
Link: CVE-2026-50244
No data.
OpenCVE Enrichment
No data.