Executive brief
The Naxclow IoT platform, which manages smart home devices like doorbells and cameras, contains a security flaw in its cloud interface. This flaw allows unauthorized individuals to retrieve sensitive login credentials for any device on the platform. An attacker could use these credentials to impersonate a device, allowing them to intercept private communications or disrupt the service for the legitimate owner.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Naxclow platform API responsible for returning device relay registration details. The API endpoint fails to verify if the requester is the legitimate owner or the device itself before returning persistent credentials. An attacker capable of generating a platform-valid request signature can retrieve these credentials for arbitrary devices. Once obtained, the attacker can register on the relay as the target device, enabling the interception and disruption of device communications. As of the advisory date, the vendor has not responded to coordination attempts, and no patch is available.
Affected products
- Naxclow IoT Platform All versions
- Naxclow Smart Doorbell X3 All versions
- Naxclow X Smart Home All versions
- Naxclow V720 All versions
- Naxclow ix cam All versions
Timeline
- 2026-06-11: advisory: CISA published ICS Advisory ICSA-26-162-02
- 2026-06-12: disclosed: CVE-2026-50108 published to the NVD