CVE-2026-50101
Last modified
CVE-2026-50101 is a critical-severity vulnerability rated 9.2/10 on the CVSS scale. Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any exposure path can maintain persistent access to the device’s relay channel. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any exposure path can maintain persistent access to the device’s relay channel. This enables long-term impersonation or interception, even after factory resets or re-onboarding.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-50101?
How severe is CVE-2026-50101?
How do I fix CVE-2026-50101?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-50089The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an…6.1
- CVE-2026-50090The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.…6.1
- CVE-2026-50091Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and whi…7.4
- CVE-2026-50099During WiFi association, Naxclow device firmware prints the …5.1
- CVE-2026-5010A reflected Cross-Site Scripting (XSS) vulnerability has bee…5.1
- CVE-2026-50100Multiple printer drivers provided by Ricoh Company, Ltd. and…8.5
- CVE-2026-50103A NULL pointer dereference in the L2 GOOSE and R-GOOSE share…7.1
- CVE-2026-50107When NGINX Plus or NGINX Open Source is configured as the da…8.6
- CVE-2026-50108The Naxclow platform API that returns device relay registrat…8.7
- CVE-2026-5011A vulnerability was detected in elecV2 elecV2P up to 3.8.3. …6.3
- CVE-2026-50110Storage Concentrator (SC & SCVM) contains hardcoded credenti…9.3
- CVE-2026-5012A flaw has been found in elecV2 elecV2P up to 3.8.3. This is…7.3
Are you affected by CVE-2026-50101?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
