High severity7.5NVD Advisory· Published Jun 12, 2026· Updated Jun 16, 2026
CVE-2026-50108
CVE-2026-50108
Description
The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary devices and register on the relay as that device, enabling interception and disruption of its communications.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
2- CISA Discloses 8 CVEs Across Naxclow IoT and Brickcom Cameras, Including Critical Hard-Coded Salt FlawVypr Intelligence · Jun 12, 2026
- Naxclow IoT PlatformCISA ICS Advisories