Junglewise Threat Intelligence

CVE-2026-42947: Naxclow IoT Platform authorization bypass in onboarding workflow

CVE-2026-42947 · Severity: high · CVSS 8.8 · Published 2026-06-12

Technologies: Naxclow X Smart Home, Naxclow Ix Cam, Naxclow Smart Doorbell X3, Naxclow V720. Vendors: Naxclow.

Executive brief

A security flaw in the Naxclow IoT platform's device setup process allows unauthorized users to hijack smart home devices, such as doorbells and cameras. By replaying specific setup commands, an attacker can silently reassign a device to their own account without the legitimate owner's knowledge. This could lead to unauthorized surveillance, access to private video feeds, and complete loss of control over the affected smart home hardware.

Technical details

The vulnerability is classified as an Authorization Bypass Through User-Controlled Key (CWE-639) within the Naxclow IoT platform's onboarding workflow. The root cause is a failure in the 'confirm-then-bind' sequence where the platform validates request signatures but fails to verify the legitimate ownership of the device being bound. An attacker with a valid platform account can replay this sequence to silently reassign a target device to their own account. This attack can be executed over the network without user interaction, and the device remains operational and unaware of the change in ownership. As of the advisory date, the vendor has not responded to coordination attempts, and no official patch is available.

Affected products

  • Naxclow Smart Doorbell X3 all
  • Naxclow X Smart Home all
  • Naxclow V720 all
  • Naxclow ix cam all

Timeline

  • 2026-06-11: advisory: CISA ICSA-26-162-02 published
  • 2026-06-12: disclosed: CVE-2026-42947 published in NVD

References

Related threats