PT-2026-48951 · Naxclow · Smart Doorbell X3

CVE-2026-28742

·

Published

2026-06-12

·

Updated

2026-06-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Naxclow Smart Doorbell X3 (affected versions not specified) Naxclow devices (affected versions not specified)
Description Naxclow devices utilize a uniform request-signing scheme that relies on a hard-coded, platform-wide salt embedded in every firmware image. The absence of per-device keys, server-side nonce tracking, or replay protections allows an attacker who recovers this salt to generate valid signatures for arbitrary device or account operations. This issue is further exacerbated by the use of plain HTTP for control-plane traffic, enabling broad request forgery and impersonation across the platform. Real-world offensive activities targeting the Smart Doorbell X3 and other products have been identified.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28742

Affected Products

Smart Doorbell X3