Junglewise Threat Intelligence

CVE-2026-50099: Naxclow IoT devices sensitive information disclosure via UART console

CVE-2026-50099 · Severity: medium · CVSS 4.6 · Published 2026-06-12

Technologies: Naxclow X Smart Home, Naxclow Ix Cam, Naxclow Smart Doorbell X3, Naxclow V720. Vendors: Naxclow.

Executive brief

Naxclow smart home devices, including doorbells and cameras, leak sensitive network information through a physical connection point on the hardware. An attacker with brief physical access to the device can retrieve the owner's WiFi name and password in plain text. This could allow an intruder to gain access to the home network or extract the device's internal software for further attacks.

Technical details

Naxclow device firmware contains an information disclosure vulnerability where sensitive WiFi association data, including the SSID, PSK, and negotiated WPA keys, are printed in cleartext to an exposed UART console. The UART pads on production hardware are labeled and utilize default serial settings. Upon connection, the device provides an interactive RT-Thread shell that allows for arbitrary memory reads and full firmware extraction. An attacker with physical access can exploit this to recover network credentials or facilitate deeper reverse engineering. As of the advisory date, the vendor has not responded to coordination attempts, and no official patch is available.

Affected products

  • Naxclow Smart Doorbell X3 All versions
  • Naxclow X Smart Home All versions
  • Naxclow V720 All versions
  • Naxclow ix cam All versions

Timeline

  • 2026-06-11: advisory: CISA published ICSA-26-162-02
  • 2026-06-12: disclosed: CVE-2026-50099 published in NVD

References

Related threats