By weakness (CWE)
CWE-262: related vulnerabilities
CVEs classified under CWE-262. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
1 published vulnerability
- CVE-2026-50101HIGH 8.1
Naxclow relay devices contain a critical credential management flaw that compromises long-term security. Each device is issued a server-side relay credential at boot time that never changes and cannot be revoked—even by the device owner. If an attacker gains access to this credential through any means (network interception, leaked documentation, compromised backups, or previous breaches), they retain the ability to impersonate the device indefinitely. Factory resets and device re-onboarding do not invalidate the compromised credential, meaning a single credential exposure can lead to persistent unauthorized access to the device's relay channel.