Junglewise Threat Intelligence

CVE-2026-50101: Naxclow IoT Platform static relay credentials in multiple devices

CVE-2026-50101 · Severity: high · CVSS 8.1 · Published 2026-06-12

Technologies: Naxclow IoT Platform, Naxclow X Smart Home, Naxclow Ix Cam, Naxclow Smart Doorbell X3, Naxclow V720. Vendors: Naxclow.

Executive brief

Naxclow smart home devices, including doorbells and cameras, use permanent security credentials that never expire or change. If these credentials are stolen or leaked, an unauthorized person can permanently monitor or impersonate the device. This access remains active even if the owner performs a factory reset or re-registers the device.

Technical details

The vulnerability is classified as CWE-262 (Not Using Password Aging). Naxclow IoT devices utilize a static, per-device relay credential for communication that is re-issued upon every boot cycle without rotation. Because the server-side platform does not support credential revocation or expiration, any actor who obtains the credential can maintain persistent access to the device's relay channel. This allows for long-term interception of data or device impersonation. The attack is reachable over the network, though it requires the attacker to first obtain the static credential through other exposure paths. No patch is currently available as the vendor did not respond to coordination efforts.

Affected products

  • Naxclow Smart Doorbell X3 All versions
  • Naxclow X Smart Home All versions
  • Naxclow V720 All versions
  • Naxclow ix cam All versions
  • Naxclow IoT Platform All versions

Timeline

  • 2026-06-11: advisory: CISA ICSA-26-162-02 published
  • 2026-06-12: disclosed: CVE-2026-50101 published in NVD

References

Related threats