Executive brief
The Naxclow IoT platform, which manages smart home devices like doorbells and cameras, contains a flaw in its registration system. An unauthorized person can use this flaw to map out and count all active devices on the network. This information could be used to identify targets for more sophisticated attacks or to monitor the growth and scale of the manufacturer's customer base.
Technical details
The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier without validating ownership relationships (CWE-862). Each request triggers the creation of a new sequential device identifier and returns the current high-water counter value for that batch. This behavior allows unauthenticated remote attackers to programmatically measure and enumerate the entire active device space. The vulnerability stems from the use of predictable, sequential identifiers combined with a lack of authorization checks on the registration API. As of the advisory date, the vendor has not responded to coordination attempts, and no official patch is available.
Affected products
- Naxclow Smart Doorbell X3 All versions
- Naxclow X Smart Home All versions
- Naxclow V720 All versions
- Naxclow ix cam All versions
Timeline
- 2026-06-11: advisory: CISA published ICSA-26-162-02
- 2026-06-12: disclosed: CVE-2026-50244 published to NVD