github.com
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-162-02.json CVE-2026-42932
MEDIUM
Naxclow IoT Platform Generation of Predictable Numbers or Identifiers
Record summary
CVE-2026-42932 has a selected CVSS score of 6.9 (medium).
Description
Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endpoint that reveals the current identifier high-water mark, the active fleet can be enumerated.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 12, 2026 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Smart Doorbell X3Browse Naxclow / Smart Doorbell X3Default status: unaffected | CVE List | All versions | affected |
Default status: unaffected | CVE List | All versions | affected |
X Smart HomeBrowse Naxclow / X Smart HomeDefault status: unaffected | CVE List | All versions | affected |
ix camBrowse Naxclow / ix camDefault status: unaffected | CVE List | All versions | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-42932 cisa.gov
https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-02