CVE-2023-1749: Getnexx Nxal-100 Firmware
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could send API requests that the affected devices would execute.
Affected products
- Getnexx Nxal-100 Firmware: up to and including nxal100v-p1-9-1
- Getnexx Nxg-100b Firmware: up to and including nxg100bv-p3-4-1
- Getnexx Nxg-200 Firmware: up to and including nxg200v-p3-4-1
- Getnexx Nxpg-100w Firmware: up to and including nxpg100cv4-0-0
Published 2023-04-04. Last modified 2026-06-17.