CRITICAL🇵🇱 Wersja polska

CVE-2026-50101

CVSS 9.2v4.0pub. 2026-06-12upd. 2026-06-16

Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any exposure path can maintain persistent access to the device’s relay channel. This enables long-term impersonation or interception, even after factory resets or re-onboarding.

🤖 AI Analysis
How it works

On each Naxclow device, relay credentials are generated on the server side, assigned to a specific device, and reissued with every boot. These credentials never expire, are not rotated, and cannot be reset or revoked by the device owner. This means that any party who obtains these credentials by any means (e.g., through communication interception, data leak, or physical access to the device) can use them indefinitely. Importantly, even restoring the device to factory settings or re-onboarding does not invalidate the intercepted credentials.

Impact

An attacker who obtains relay credentials can persistently impersonate a device or intercept its communications, maintaining permanent access to the relay channel even after factory reset or device reconfiguration by the owner.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. It is recommended to monitor updates within the CISA ICS ICSA-26-162-02 advisory (https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-02) and implement a relay credential rotation and revocation mechanism on the server side if the manufacturer provides an appropriate firmware or configuration update.

Who is affected

Naxclow devices — specific versions indicated in the manufacturer's references (advisory ICSA-26-162-02).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References