CVE-2026-50108 Details
Description
The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary devices and register on the relay as that device, enabling interception and disruption of its communications.
A vulnerability in the Naxclow IoT platform API allows for the unauthorized retrieval of device relay registration credentials. This issue arises because the API does not verify whether the requester is the legitimate device owner. An actor who can present a valid request signature can access credentials for any device, enabling them to register as that device on the relay and intercept or disrupt its communications. This vulnerability affects all versions of the Naxclow IoT platform, including the Smart Doorbell X3, X Smart Home, V720, and ix cam.
Naxclow did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Naxclow for more information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-162-02.json | [email protected] | AdvisoryBundleRemedy |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-02 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Naxclow Smart Doorbell X3 | <= 0 |
CPE
Remediation
| |
| Naxclow X Smart Home | <= 0 |
CPE
Remediation
| |
| Naxclow V720 | <= 0 |
CPE
Remediation
| |
| Naxclow ix cam | <= 0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |
Volerion