CyberSec.Space Logo
返回 CVE 浏览器

CVE-2026-42947

HIGH
8.8
CVSS Severity Score
EPSS Score0.0980%
EPSS Percentile35.33th
Published2026年6月12日
Last Modified2026年6月12日

Vulnerability Description

A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints validate request signatures but do not confirm legitimate ownership, an attacker with any account can take over a device without user interaction while the device remains online and unaware.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相关漏洞威胁