Medium severity5.3NVD Advisory· Published Jun 12, 2026· Updated Jun 16, 2026
CVE-2026-42932
CVE-2026-42932
Description
Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endpoint that reveals the current identifier high-water mark, the active fleet can be enumerated.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
2- CISA Discloses 8 CVEs Across Naxclow IoT and Brickcom Cameras, Including Critical Hard-Coded Salt FlawVypr Intelligence · Jun 12, 2026
- Naxclow IoT PlatformCISA ICS Advisories