CVE-2026-50244 Details
Description
The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequential device identifier and returns the current high-water counter value for the batch, allowing callers to measure and enumerate the active device space. The endpoint’s behavior enables precise fleet enumeration.
A vulnerability in the Naxclow IoT platform's registration endpoint allows for fleet enumeration by accepting signed requests with a batch prefix and a caller-supplied account identifier, without validating ownership. This endpoint mints new device identifiers and returns a high-water counter value for the batch, enabling precise measurement and enumeration of active devices. The vulnerability is present in all versions of the Naxclow IoT platform, including the Smart Doorbell X3, X Smart Home, V720, and ix cam.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-162-02.json | [email protected] | AdvisoryBundleRemedy |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-02 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Naxclow Smart Doorbell X3 | <= 0 |
CPE
Remediation
| |
| Naxclow X Smart Home | <= 0 |
CPE
Remediation
| |
| Naxclow V720 | <= 0 |
CPE
Remediation
| |
| Naxclow ix cam | <= 0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |
Volerion