Executive brief
Naxclow smart home devices, including doorbells and cameras, use permanent security credentials that never expire or change. If these credentials are stolen or leaked, an unauthorized person can permanently monitor or impersonate the device. This access remains active even if the owner performs a factory reset or re-registers the device.
Technical details
The vulnerability is classified as CWE-262 (Not Using Password Aging). Naxclow IoT devices utilize a static, per-device relay credential for communication that is re-issued upon every boot cycle without rotation. Because the server-side platform does not support credential revocation or expiration, any actor who obtains the credential can maintain persistent access to the device's relay channel. This allows for long-term interception of data or device impersonation. The attack is reachable over the network, though it requires the attacker to first obtain the static credential through other exposure paths. No patch is currently available as the vendor did not respond to coordination efforts.
Affected products
- Naxclow Smart Doorbell X3 All versions
- Naxclow X Smart Home All versions
- Naxclow V720 All versions
- Naxclow ix cam All versions
- Naxclow IoT Platform All versions
Timeline
- 2026-06-11: advisory: CISA ICSA-26-162-02 published
- 2026-06-12: disclosed: CVE-2026-50101 published in NVD