CVE-2026-42947
Received Received - Intake
Naxclow Platform Account Takeover via Replay Attack

Publication date: 2026-06-12

Last updated on: 2026-06-12

Assigner: ICS-CERT

Description
A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints validate request signatures but do not confirm legitimate ownership, an attacker with any account can take over a device without user interaction while the device remains online and unaware.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-12
Last Modified
2026-06-12
Generated
2026-06-13
AI Q&A
2026-06-12
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
naxclow platform *
naxclow device *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a flaw in Naxclow's platform onboarding workflow that allows an attacker to replay a confirm-then-bind sequence. By doing so, the attacker can silently reassign a device to any arbitrary account without the device owner's knowledge.

The affected endpoints validate request signatures but do not verify legitimate ownership of the device. This means an attacker with any account can take over a device while it remains online and unaware, without requiring any user interaction.

Impact Analysis

This vulnerability can lead to unauthorized device takeover, allowing attackers to silently reassign devices to accounts they control.

Such unauthorized access can result in loss of control over devices, potential data breaches, and misuse of device capabilities, all without the legitimate user's knowledge.

Compliance Impact

The vulnerability in Naxclow's platform allows unauthorized device takeover without user interaction, which could lead to unauthorized access to sensitive data or systems.

Such unauthorized access and potential data compromise can negatively impact compliance with common standards and regulations like GDPR and HIPAA, which require strict controls over data access and device security.

However, the provided context and resources do not explicitly discuss the direct impact of this vulnerability on compliance with these regulations.

Mitigation Strategies

To mitigate this vulnerability, it is recommended to minimize network exposure of affected Naxclow devices and isolate control systems from untrusted networks.

Use secure remote access methods such as VPNs to access these devices.

Implement cybersecurity best practices to reduce the risk of exploitation.

Since Naxclow has not responded to coordination attempts, users should contact the vendor for any available remediation or patches.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-42947. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart