CVE-2026-42947 Details
Description
A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints validate request signatures but do not confirm legitimate ownership, an attacker with any account can take over a device without user interaction while the device remains online and unaware.
A vulnerability in Naxclow's IoT platform onboarding workflow enables an attacker to replay a confirm-then-bind sequence, silently reassigning a device to an arbitrary account. This issue arises because the affected endpoints validate request signatures without confirming legitimate ownership. As a result, an attacker with any account can take over a device without user interaction, while the device remains online and unaware. This vulnerability affects all versions of the Naxclow IoT Platform, including the Smart Doorbell X3, X Smart Home, V720, and ix cam.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Naxclow Smart Doorbell X3 | <= 0 |
CPE
Remediation
| |
| Naxclow X Smart Home | <= 0 |
CPE
Remediation
| |
| Naxclow V720 | <= 0 |
CPE
Remediation
| |
| Naxclow ix cam | <= 0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |
Volerion