Threats Tagged 'cve-2026-50099'
View all threats tagged with 'cve-2026-50099'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-50099'
Click on any threat for detailed analysis and mitigation recommendations
0 During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production hardware. The UART pads are labeled, run with default serial settings, and drop to an interactive RT-Thread shell that permits arbitrary memory reads, enabling full firmware extraction. An attacker with brief physical access, common for outdoor-mounted devices, can therefore recover WiFi credentials and bootstrap firmware-side attacks. Join the discussion | CVE Database V5 | 06/12/2026, 18:24:14 UTC Added: 06/12/2026, 18:55:14 UTC |
0 CVE-2026-42947 is a high-severity authorization bypass vulnerability in the Naxclow Smart Doorbell X3. The flaw exists in the onboarding workflow, allowing an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. The affected endpoints validate request signatures but do not verify legitimate ownership, enabling attackers with any account to take over devices without user interaction while the device remains online and unaware. Join the discussion | GCVE Database | 06/12/2026, 18:13:41 UTC Added: 06/12/2026, 11:14:35 UTC |
Showing 1 to 2 of 2 results