# Naxclow IoT Devices Can Be Silently Hijacked—Vendor Remains Unresponsive to Critical Flaws


## The Threat


A coordinated disclosure failure has exposed millions of Naxclow IoT devices worldwide to complete takeover attacks. Three critical vulnerabilities in Naxclow's IoT platform allow attackers to silently reassign devices to arbitrary accounts, harvest device credentials at scale, and maintain persistent access even after factory resets. The flaws span the entire Naxclow product line—including Smart Doorbells, cameras, and smart home hubs—and affect all firmware versions currently in the wild.


The vulnerabilities form a perfect storm. An attacker can replay authentication sequences to steal a device from its legitimate owner without any user interaction (CVE-2026-42947), then leverage stolen credentials to intercept and manipulate communications with Naxclow's relay servers (CVE-2026-50108). Once compromised, the attacker gains access to relay credentials that never expire and cannot be revoked—meaning a single stolen credential grants indefinite persistence, even if the victim factory-resets the device or re-onboards it to a new account (CVE-2026-50101).


The problem is made worse by Naxclow's silence. When CISA reached out to coordinate responsible disclosure, Naxclow did not respond. No patches have been released. No timeline for fixes has been announced. For organizations and homeowners relying on Naxclow devices for security and automation, the situation is stark: the devices are actively vulnerable with no vendor support available.


## Severity and Impact


| Item | Details |

|------|---------|

| Affected Vendor | Naxclow (China-based) |

| CVE-2026-42947 | Authorization Bypass Through Replay Attack |

| CVE-2026-50108 | Missing Authorization on Credential Exposure |

| CVE-2026-50101 | Non-Rotating Device Credentials |

| CVSS Scores | 8.8 (CVSS v3.1) to 8.7 (CVSS v4.0) across all three CVEs |

| Severity Rating | HIGH (all three vulnerabilities) |

| Attack Vector | Network |

| Attack Complexity | Low (except CVE-2026-42947, which requires High complexity) |

| Authentication Required | Low privilege account sufficient for CVE-2026-42947 and CVE-2026-50101; None for CVE-2026-50108 |

| User Interaction | None required |

| Impact | Complete device compromise, credential theft, persistent access, traffic interception |

| CWE-639 | Authorization Bypass Through User-Controlled Key |

| CWE-862 | Missing Authorization |

| CWE-262 | Not Using Password Aging |


## Affected Products


All versions of the following Naxclow products are affected:


  • Naxclow Smart Doorbell X3 – all versions
  • Naxclow X Smart Home – all versions
  • Naxclow V720 – all versions
  • Naxclow ix cam – all versions

  • These devices are deployed globally across commercial facilities and residential installations. Naxclow's China-based headquarters indicates significant market penetration in Asia, but the platform's reach extends to North America, Europe, and other regions.


    ## Mitigations


    ### Immediate Actions


    Given Naxclow's lack of vendor response, defenders must implement network-level protections:


  • Network Segmentation: Isolate Naxclow IoT devices on a dedicated VLAN or network segment with restricted egress. Prevent direct communication to other smart home or office network resources.
  • Firewall Rules: Restrict outbound connections from Naxclow devices to only essential services. Block relay server communication if the devices can function in local-only mode.
  • Monitor for Tampering: Watch device onboarding logs and account activity. A sudden re-pairing to a different user account or unexpected relay credential updates may indicate compromise.
  • Credential Rotation (Where Possible): If your smart home system allows credential reset, force a reset immediately, then re-onboard in the most isolated network configuration available.

  • ### Long-Term Options


  • Device Replacement: Plan to migrate to IoT platforms from vendors with active security practices and timely vulnerability response. Naxclow's silence indicates a vendor that will not support devices reactively.
  • Contact Naxclow: Request security updates directly. Document that you attempted to obtain patches; this will be important for compliance and incident response audits.
  • Prepare Incident Response: If you manage Naxclow devices in a commercial environment, update your incident response plan to include device takeover detection and credential revocation procedures.

  • ## References


  • [CISA NVD CVE-2026-42947 Details](#)
  • [CISA NVD CVE-2026-50108 Details](#)
  • [CISA NVD CVE-2026-50101 Details](#)
  • Naxclow IoT Platform Security Advisory (vendor contact recommended; no public advisory currently available)

  • ---


    ## HackWire Analysis


    This disclosure exposes a systemic failure in IoT vendor accountability. Naxclow's non-responsiveness to CISA's coordination attempt is not a minor oversight—it signals a company that either lacks security infrastructure to respond to disclosures or actively chose not to engage. Either way, customers are left defenseless.


    The vulnerability chain is instructive for why IoT security is broken at scale. Each individual flaw—weak onboarding validation, missing authorization checks, non-expiring credentials—is a textbook mistake. Together, they form a complete attack path: silently hijack a device, harvest its relay credentials, and maintain permanent persistence without the owner's knowledge.


    What makes this particularly dangerous is the relay architecture. Most smart home exploits are noisy—they require active communication or user-visible behavior changes. This attack is silent. An attacker can take over a doorbell or camera, and the legitimate owner won't know until the device stops responding to their commands or they notice unexpected relay activity. By then, the attacker has weeks or months of video footage, microphone access, or control over physical locks.


    The global deployment scope compounds the risk. Naxclow may not be a household name like Ring or Google, but the company competes aggressively in emerging markets and contract smart home installations. A single compromise can affect dozens of connected locations simultaneously.


    The playbook here matters too. When a vendor goes silent, it signals to researchers that disclosure timelines and patch commitments are performative. This creates a perverse incentive: find more vulnerabilities before disclosure closes, because public knowledge is your only leverage for a fix. Naxclow's silence may result in rapid release of additional flaws, further eroding trust.


    For defenders: if you have Naxclow devices, inventory them now. If they're on your corporate network or handling sensitive operations (building access, surveillance, HVAC), isolate them aggressively. If you can replace them, do it. Vendors that don't respond to CISA won't respond to your incident, either.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)