CVE-2026-50108: Naxclow Ix Cam
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary devices and register on the relay as that device, enabling interception and disruption of its communications.
Affected products
- Naxclow Ix Cam: any version
- Naxclow Smart Doorbell x3: any version
- Naxclow v720: any version
- Naxclow X Smart Home: any version
Published 2026-06-12. Last modified 2026-06-17.