Executive brief
Naxclow smart home devices, including doorbells and cameras, use a single shared security key across all units worldwide. An attacker who discovers this key can impersonate any user or device, potentially gaining unauthorized access to video feeds or account settings. Because the system also lacks modern encryption for its control traffic, these unauthorized commands can be sent easily over the internet.
Technical details
The vulnerability stems from the use of a hard-coded cryptographic salt (CWE-321) shared across all Naxclow firmware images for request signing. Because the platform lacks per-device keys, server-side nonce tracking, or replay protections, an attacker who extracts the salt from any single device can generate valid signatures for arbitrary account or device operations. This is further exacerbated by the use of unencrypted HTTP for control-plane traffic, allowing a remote, unauthenticated attacker to perform large-scale request forgery and impersonation. As of the advisory date, the vendor has not responded to coordination attempts, and no official patch is available.
Affected products
- Naxclow Smart Doorbell X3 All versions
- Naxclow X Smart Home All versions
- Naxclow V720 All versions
- Naxclow ix cam All versions
- Naxclow IoT Platform All versions
Timeline
- 2026-06-11: advisory: CISA ICSA-26-162-02 published
- 2026-06-12: disclosed: CVE-2026-28742 published in NVD