Junglewise Threat Intelligence

CVE-2026-42932: Naxclow IoT Platform predictable device identifier generation

CVE-2026-42932 · Severity: medium · CVSS 5.3 · Published 2026-06-12

Technologies: Naxclow IoT Platform, Naxclow X Smart Home, Naxclow Ix Cam, Naxclow Smart Doorbell X3, Naxclow V720. Vendors: Naxclow.

Executive brief

The Naxclow IoT platform, which manages smart home devices like doorbells and cameras, uses predictable identification numbers for its hardware. Because these IDs are sequential and the platform publicly reveals the total number of registered devices, an attacker can easily map out and identify every active device in the company's fleet. This information can be used as a starting point for more targeted attacks against specific users or hardware.

Technical details

The vulnerability is a case of predictable identifier generation (CWE-340) within the Naxclow IoT Platform. Device IDs are constructed using static manufacturing prefixes followed by sequential counters. Furthermore, a platform endpoint reveals the 'high-water mark' (the highest current ID), allowing a remote, unauthenticated attacker to systematically enumerate the entire active device fleet via the network. This enumeration can facilitate targeted exploitation when combined with other vulnerabilities in the platform's authorization or communication protocols. As of the advisory date, the vendor has not responded to coordination attempts, and no official patch is available.

Affected products

  • Naxclow Smart Doorbell X3 All versions
  • Naxclow X Smart Home All versions
  • Naxclow V720 All versions
  • Naxclow ix cam All versions
  • Naxclow IoT Platform All versions

Timeline

  • 2026-06-11: advisory: CISA ICSA-26-162-02 published
  • 2026-06-12: disclosed: CVE-2026-42932 published in NVD

References

Related threats