Metrics
Affected Vendors & Products
Fri, 12 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Naxclow
Naxclow ix Cam Naxclow smart Doorbell X3 Naxclow v720 Naxclow x Smart Home |
|
| Vendors & Products |
Naxclow
Naxclow ix Cam Naxclow smart Doorbell X3 Naxclow v720 Naxclow x Smart Home |
Fri, 12 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary devices and register on the relay as that device, enabling interception and disruption of its communications. | |
| Title | Naxclow IoT Platform Missing Authorization | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-06-12T19:01:28.533Z
Reserved: 2026-06-08T20:04:55.525Z
Link: CVE-2026-50108
Updated: 2026-06-12T19:01:24.840Z
Status : Received
Published: 2026-06-12T19:16:29.633
Modified: 2026-06-12T19:16:29.633
Link: CVE-2026-50108
No data.
OpenCVE Enrichment
Updated: 2026-06-12T20:19:23Z