PT-2026-48959 · Naxclow · Smart Doorbell X3+3

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-50244

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequential device identifier and returns the current high-water counter value for the batch, allowing callers to measure and enumerate the active device space. The endpoint’s behavior enables precise fleet enumeration.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-50244

Affected Products

Smart Doorbell X3
V720
Smarthome
Ix Cam