Naxclow Smart Doorbell X3是Naxclow的一个智能家居视频门铃。 Naxclow Smart Doorbell X3存在配置错误漏洞,该漏洞源于使用永不过期且无法重置或撤销的服务器端每设备中继凭证,导致任何获取该凭证的方可以长期保持对设备中继通道的访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Naxclow | ix cam | All |
affected |
| Naxclow | Smart Doorbell X3 | All |
affected |
| Naxclow | V720 | All |
affected |
| Naxclow | X Smart Home | All |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Naxclow | Smart Doorbell X3 | All | - |
|
| Naxclow | X Smart Home | All | - |
|
| Naxclow | V720 | All | - |
|
| Naxclow | ix cam | All | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28742 | 9.8 CRITICAL | Naxclow IoT Platform Use of hard-coded cryptographic key |
| CVE-2026-42947 | 8.8 HIGH | Naxclow IoT Platform Authorization bypass through User-Controlled key |
| CVE-2026-50108 | 7.5 HIGH | Naxclow IoT Platform Missing Authorization |
| CVE-2026-42932 | 5.3 MEDIUM | Naxclow IoT Platform Generation of Predictable Numbers or Identifiers |
| CVE-2026-50244 | 5.3 MEDIUM | Naxclow IoT Platform Missing Authorization |
| CVE-2026-50099 | 4.6 MEDIUM | Naxclow IoT Platform Insertion of sensitive information into Externally-Accessible file or |
No comments yet