Naxclow Smart Doorbell X3是Naxclow的一个智能家居视频门铃。 Naxclow Smart Doorbell X3存在授权问题漏洞,该漏洞源于平台的上线工作流中允许攻击者重放确认-绑定序列,将设备静默重新分配给任意账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Naxclow | ix cam | All |
affected |
| Naxclow | Smart Doorbell X3 | All |
affected |
| Naxclow | V720 | All |
affected |
| Naxclow | X Smart Home | All |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Naxclow | Smart Doorbell X3 | All | - |
|
| Naxclow | X Smart Home | All | - |
|
| Naxclow | V720 | All | - |
|
| Naxclow | ix cam | All | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28742 | 9.8 CRITICAL | Naxclow IoT Platform Use of hard-coded cryptographic key |
| CVE-2026-50101 | 8.1 HIGH | Naxclow IoT Platform Not using password aging |
| CVE-2026-50108 | 7.5 HIGH | Naxclow IoT Platform Missing Authorization |
| CVE-2026-42932 | 5.3 MEDIUM | Naxclow IoT Platform Generation of Predictable Numbers or Identifiers |
| CVE-2026-50244 | 5.3 MEDIUM | Naxclow IoT Platform Missing Authorization |
| CVE-2026-50099 | 4.6 MEDIUM | Naxclow IoT Platform Insertion of sensitive information into Externally-Accessible file or |
No comments yet