CVE-2026-50101 Details
Description
Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any exposure path can maintain persistent access to the device’s relay channel. This enables long-term impersonation or interception, even after factory resets or re-onboarding.
A vulnerability exists in Naxclow IoT devices due to the use of a server-side, per-device relay credential that is issued on each boot and never rotates. This credential remains valid indefinitely and cannot be reset or revoked by the device owner. As a result, any party that obtains the credential can maintain persistent access to the device's relay channel, enabling long-term impersonation or interception of communications, even after factory resets or re-onboarding. The vulnerability affects all versions of Naxclow Smart Doorbell X3, X Smart Home, V720, and ix cam devices.
Naxclow did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Naxclow for more information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-162-02.json | [email protected] | AdvisoryBundlePartial Content |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-02 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-262 | Not Using Password Aging | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Naxclow Smart Doorbell X3 | <= 0 |
CPE
Remediation
| |
| Naxclow X Smart Home | <= 0 |
CPE
Remediation
| |
| Naxclow V720 | <= 0 |
CPE
Remediation
| |
| Naxclow ix cam | <= 0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |
Volerion