www.cisa.gov 6/11/2026, 4:11:04 PM · external

Naxclow IoT Platform flaws open devices to remote hijack

CyberSIXT Evidence Panel
Primary Source github.com

THE advisory discusses security vulnerabilities in the Naxclow IoT Platform, released on June 11, 2026, with the alert code ICSA-26-162-02. Specifically, several versions of Naxclow devices, including the Smart Doorbell X3 and the X Smart Home, are at risk of exploitation, which could lead to unauthorized access, impersonation of devices, and interception of communications.

The vulnerabilities include severe issues such as authorization bypass, use of hard-coded keys, and unreliable credential management, with CVSS scores ranging from 5.3 to 9.8. The advisory recommends minimizing network exposure and implementing defensive measures to mitigate the risks.

View Primary Source Via www.cisa.gov

Article by CyberSIXT