CVE-2026-42947

A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints validate request signatures but do not confirm legitimate ownership, an attacker with any account can take over a device without user interaction while the device remains online and unaware.
Configurations

No configuration.

History

12 Jun 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 19:16

Updated : 2026-06-17 10:48


NVD link : CVE-2026-42947

Mitre link : CVE-2026-42947

CVE.ORG link : CVE-2026-42947


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key