Executive brief
A security flaw in the Naxclow IoT platform's device setup process allows unauthorized users to hijack smart home devices, such as doorbells and cameras. By replaying specific setup commands, an attacker can silently reassign a device to their own account without the legitimate owner's knowledge. This could lead to unauthorized surveillance, access to private video feeds, and complete loss of control over the affected smart home hardware.
Technical details
The vulnerability is classified as an Authorization Bypass Through User-Controlled Key (CWE-639) within the Naxclow IoT platform's onboarding workflow. The root cause is a failure in the 'confirm-then-bind' sequence where the platform validates request signatures but fails to verify the legitimate ownership of the device being bound. An attacker with a valid platform account can replay this sequence to silently reassign a target device to their own account. This attack can be executed over the network without user interaction, and the device remains operational and unaware of the change in ownership. As of the advisory date, the vendor has not responded to coordination attempts, and no official patch is available.
Affected products
- Naxclow Smart Doorbell X3 all
- Naxclow X Smart Home all
- Naxclow V720 all
- Naxclow ix cam all
Timeline
- 2026-06-11: advisory: CISA ICSA-26-162-02 published
- 2026-06-12: disclosed: CVE-2026-42947 published in NVD