CVE-2026-50108

HIGH

Naxclow IoT Platform Missing Authorization

Title source: cna
STIX 2.1

Description

The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary devices and register on the relay as that device, enabling interception and disruption of its communications.

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 33.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (4)
Naxclow/ix cam All
Naxclow/Smart Doorbell X3 All
Naxclow/V720 All
Naxclow/X Smart Home All
Published Jun 12, 2026
Tracked Since Jun 13, 2026