PT-2026-48951 · Naxclow · Smart Doorbell X3
CVE-2026-28742
·
Published
2026-06-12
·
Updated
2026-06-13
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Naxclow Smart Doorbell X3 (affected versions not specified)
Naxclow devices (affected versions not specified)
Description
Naxclow devices utilize a uniform request-signing scheme that relies on a hard-coded, platform-wide salt embedded in every firmware image. The absence of per-device keys, server-side nonce tracking, or replay protections allows an attacker who recovers this salt to generate valid signatures for arbitrary device or account operations. This issue is further exacerbated by the use of plain HTTP for control-plane traffic, enabling broad request forgery and impersonation across the platform. Real-world offensive activities targeting the Smart Doorbell X3 and other products have been identified.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smart Doorbell X3