github.com
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-162-02.json CVE-2026-50244
MEDIUM
Naxclow IoT Platform Missing Authorization
Record summary
CVE-2026-50244 has a selected CVSS score of 6.9 (medium).
Description
The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequential device identifier and returns the current high-water counter value for the batch, allowing callers to measure and enumerate the active device space. The endpoint’s behavior enables precise fleet enumeration.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 12, 2026 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Smart Doorbell X3Browse Naxclow / Smart Doorbell X3Default status: unaffected | CVE List | All versions | affected |
Default status: unaffected | CVE List | All versions | affected |
X Smart HomeBrowse Naxclow / X Smart HomeDefault status: unaffected | CVE List | All versions | affected |
ix camBrowse Naxclow / ix camDefault status: unaffected | CVE List | All versions | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-50244 cisa.gov
https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-02