CVE-2023-1751: Getnexx Nxal-100 Firmware

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to associate. This could allow any authorized user to receive alarm information and signals meant for other devices which leak a deviceId.

Affected products

  • Getnexx Nxal-100 Firmware: up to and including nxal100v-p1-9-1
  • Getnexx Nxg-100b Firmware: up to and including nxg100bv-p3-4-1
  • Getnexx Nxg-200 Firmware: up to and including nxg200v-p3-4-1
  • Getnexx Nxpg-100w Firmware: up to and including nxpg100cv4-0-0

Published 2023-04-04. Last modified 2026-06-17.