CVE-2023-1748: Getnexx Nxal-100 Firmware

Critical severity, CVSS 10.0. EPSS: 0.8% chance of exploitation in the next 30 days.

The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.

Affected products

  • Getnexx Nxal-100 Firmware: up to and including nxal100v-p1-9-1
  • Getnexx Nxg-100b Firmware: up to and including nxg100bv-p3-4-1
  • Getnexx Nxg-200 Firmware: up to and including nxg200v-p3-4-1
  • Getnexx Nxpg-100w Firmware: up to and including nxpg100cv4-0-0

Published 2023-04-04. Last modified 2026-06-17.