Description
Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endpoint that reveals the current identifier high-water mark, the active fleet can be enumerated.
Problem types
CWE-340 Generation of Predictable Numbers or Identifiers
Product status
All
All
All
All
Credits
Temuri Takalandze reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-162-02
github.com/...p/csaf_files/OT/white/2026/icsa-26-162-02.json