CVE-2026-50244

MEDIUM

Naxclow IoT Platform Missing Authorization

Title source: cna
STIX 2.1

Description

The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequential device identifier and returns the current high-water counter value for the batch, allowing callers to measure and enumerate the active device space. The endpoint’s behavior enables precise fleet enumeration.

Scores

CVSS v3 5.3
EPSS 0.0019
EPSS Percentile 9.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (4)
Naxclow/ix cam All
Naxclow/Smart Doorbell X3 All
Naxclow/V720 All
Naxclow/X Smart Home All
Published Jun 12, 2026
Tracked Since Jun 13, 2026