Naxclow IoT Vulnerabilities: 7 Flaws Let Attackers Hijack Doorbells and Cameras
ID: 5b7d2317-a4b1-58d6-a24d-af4595571997
STIX ID: report--5b7d2317-a4b1-58d6-a24d-af4595571997
Feed Name: securityonline.info
This advisory describes seven critical vulnerabilities in Naxclow smart doorbells and cameras—most notably a platform-wide hard-coded signing salt (CVE-2026-28742) and use of plain HTTP—which combined allow attackers to forge requests, hijack devices, intercept video, enumerate the fleet, and exfiltrate WiFi credentials (including via an exposed UART). No vendor patch or response has been provided; users are advised to isolate affected devices, block internet access, and consider retiring them.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
