CVE-2026-28742
Naxclow IoT Platform Use of hard-coded cryptographic key
Record summary
CVE-2026-28742 has a selected CVSS score of 9.2 (critical).
Description
Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any device, an attacker can generate valid signatures for arbitrary device or account operations due to the absence of per-device keys, server-side nonce tracking, or replay protections. Combined with the system’s use of plain HTTP for control-plane traffic, the construction enables broad request forgery and impersonation across the platform.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 12, 2026 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Smart Doorbell X3Browse Naxclow / Smart Doorbell X3Default status: unaffected | CVE List | All versions | affected |
Default status: unaffected | CVE List | All versions | affected |
X Smart HomeBrowse Naxclow / X Smart HomeDefault status: unaffected | CVE List | All versions | affected |
ix camBrowse Naxclow / ix camDefault status: unaffected | CVE List | All versions | affected |