Naxclow Smart Doorbell X3是Naxclow的一个智能家居视频门铃。 Naxclow Smart Doorbell X3存在信息泄露漏洞,该漏洞源于固件在WiFi关联过程中将SSID、PSK和WPA密钥以明文形式输出到暴露的UART控制台,且UART接口允许任意内存读取,可能导致具有物理访问权限的攻击者恢复WiFi凭证并启动固件侧攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Naxclow | ix cam | All |
affected |
| Naxclow | Smart Doorbell X3 | All |
affected |
| Naxclow | V720 | All |
affected |
| Naxclow | X Smart Home | All |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Naxclow | Smart Doorbell X3 | All | - |
|
| Naxclow | X Smart Home | All | - |
|
| Naxclow | V720 | All | - |
|
| Naxclow | ix cam | All | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28742 | 9.8 CRITICAL | Naxclow IoT Platform Use of hard-coded cryptographic key |
| CVE-2026-42947 | 8.8 HIGH | Naxclow IoT Platform Authorization bypass through User-Controlled key |
| CVE-2026-50101 | 8.1 HIGH | Naxclow IoT Platform Not using password aging |
| CVE-2026-50108 | 7.5 HIGH | Naxclow IoT Platform Missing Authorization |
| CVE-2026-42932 | 5.3 MEDIUM | Naxclow IoT Platform Generation of Predictable Numbers or Identifiers |
| CVE-2026-50244 | 5.3 MEDIUM | Naxclow IoT Platform Missing Authorization |
No comments yet