Naxclow Smart Doorbell X3是Naxclow的一个智能家居视频门铃。 Naxclow Smart Doorbell X3存在加密问题漏洞,该漏洞源于设备标识符使用固定的制造前缀结合顺序计数器,产生完全可预测和可枚举的标识符空间,同时平台暴露端点揭示当前标识符高水位标记,可能导致活动设备被枚举。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Naxclow | ix cam | All |
affected |
| Naxclow | Smart Doorbell X3 | All |
affected |
| Naxclow | V720 | All |
affected |
| Naxclow | X Smart Home | All |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Naxclow | Smart Doorbell X3 | All | - |
|
| Naxclow | X Smart Home | All | - |
|
| Naxclow | V720 | All | - |
|
| Naxclow | ix cam | All | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28742 | 9.8 CRITICAL | Naxclow IoT Platform Use of hard-coded cryptographic key |
| CVE-2026-42947 | 8.8 HIGH | Naxclow IoT Platform Authorization bypass through User-Controlled key |
| CVE-2026-50101 | 8.1 HIGH | Naxclow IoT Platform Not using password aging |
| CVE-2026-50108 | 7.5 HIGH | Naxclow IoT Platform Missing Authorization |
| CVE-2026-50244 | 5.3 MEDIUM | Naxclow IoT Platform Missing Authorization |
| CVE-2026-50099 | 4.6 MEDIUM | Naxclow IoT Platform Insertion of sensitive information into Externally-Accessible file or |
No comments yet