Back to CVE List

CVE-2026-28742

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any device, an attacker can generate valid signatures for arbitrary device or account operations due to the absence of per-device keys, server-side nonce tracking, or replay protections. Combined with the system’s use of plain HTTP for control-plane traffic, the construction enables broad request forgery and impersonation across the platform.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-321
Source
NVD
Vendor
Naxclow
Product
Smart Doorbell X3, X Smart Home, V720, ix cam

External References

Discussion (0)

Add Comment

No comments yet. Be the first!