Project Subscriptions
No advisories yet.
Solution
Naxclow did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Naxclow for more information.
Workaround
No workaround given by the vendor.
Fri, 12 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Naxclow
Naxclow ix Cam Naxclow smart Doorbell X3 Naxclow v720 Naxclow x Smart Home |
|
| Vendors & Products |
Naxclow
Naxclow ix Cam Naxclow smart Doorbell X3 Naxclow v720 Naxclow x Smart Home |
Fri, 12 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any device, an attacker can generate valid signatures for arbitrary device or account operations due to the absence of per-device keys, server-side nonce tracking, or replay protections. Combined with the system’s use of plain HTTP for control-plane traffic, the construction enables broad request forgery and impersonation across the platform. | |
| Title | Naxclow IoT Platform Use of hard-coded cryptographic key | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-06-12T19:02:26.665Z
Reserved: 2026-06-08T20:04:55.536Z
Link: CVE-2026-28742
Updated: 2026-06-12T19:02:23.347Z
Status : Received
Published: 2026-06-12T19:16:26.743
Modified: 2026-06-12T19:16:26.743
Link: CVE-2026-28742
No data.
OpenCVE Enrichment
Updated: 2026-06-12T20:19:26Z