securityonline.info 6/16/2026, 3:47:20 AM · external

CVE-2026-28742 flaw exposes Naxclow smart devices to hijack

CVE-2026-28742 flaw exposes Naxclow smart devices to hijack
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Not in KEV
Patch Patch Status Unknown

CISA has revealed seven serious vulnerabilities in Naxclow IoT products, including popular smart doorbells and cameras, which allow attackers to hijack devices and access sensitive information. The most critical issue, CVE-2026-28742, is linked to a hard-coded key that enables request forgery across all accounts and devices. Other vulnerabilities facilitate device takeover, persistent spying, and unauthorized access to network credentials.

Users are advised to isolate affected devices and block their internet access as there are no available patches. Overall, these flaws highlight significant design weaknesses in the Naxclow platform.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline