CVE 6.9 MEDIUM

Naxclow IoT Platform Missing Authorization_CVE-2026-50244

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequential device identifier and returns the current high-water counter value for the batch, allowing callers to measure and enumerate the active device space. The endpoint’s behavior enables precise fleet enumeration.

Basic Information

ID CVE-2026-50244
Source icscert
Published Jun 12, 2026 at 18:21
Modified Jun 12, 2026 at 19:00

Affected Product

Vendor Naxclow
Product Smart Doorbell X3
Version All
Affected Versions Naxclow Smart Doorbell X3 All
Naxclow X Smart Home All
Naxclow V720 All
Naxclow ix cam All

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.