CVE-2026-42932 Details
Description
Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endpoint that reveals the current identifier high-water mark, the active fleet can be enumerated.
A vulnerability in the Naxclow IoT platform's device identifier generation allows for predictable and enumerable identifiers. This issue is present in all versions of the Smart Doorbell X3, X Smart Home, V720, and ix cam. The vulnerability is exacerbated by an exposed endpoint that reveals the current identifier high-water mark, enabling enumeration of the active device fleet. Additionally, during WiFi association, the device firmware broadcasts sensitive network information, including the SSID, PSK, and negotiated WPA keys, in cleartext over an exposed UART console. This console, accessible on production hardware, drops into an interactive RT-Thread shell that permits arbitrary memory reads, potentially leading to full firmware extraction. An attacker with brief physical access to the device could exploit this to recover WiFi credentials and initiate firmware-side attacks.
Naxclow did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Naxclow for more information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-162-02.json | [email protected] | AdvisoryBundlePartial Content |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-02 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-340 | Generation of Predictable Numbers or Identifiers | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Naxclow Smart Doorbell X3 | <= 0 |
CPE
Remediation
| |
| Naxclow X Smart Home | <= 0 |
CPE
Remediation
| |
| Naxclow V720 | <= 0 |
CPE
Remediation
| |
| Naxclow ix cam | <= 0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |
Volerion