Naxclow IoT Platform
CISA warns that multiple flaws in Naxclow's IoT platform could let attackers hijack devices, steal credentials, and intercept or alter communications.
Intelligence analysis by GPT-5.4 Mini
CISA says several serious bugs affect Naxclow smart doorbells, home devices, and cameras worldwide. The issues include authorization bypasses, hard-coded secrets, and reusable credentials that can enable device impersonation and traffic interception.
CISA found that some Naxclow smart devices use weak locks and secret codes that do not change. That can let a bad actor pretend to be the device, like copying a house key that never gets replaced.
Analysis
Overview
CISA issued an ICS advisory for Naxclow IoT Platform, warning that successful exploitation could let an attacker impersonate devices, intercept or manipulate communications, harvest sensitive credentials at scale, or gain unauthorized access. The advisory says the affected products include the Smart Doorbell X3, X Smart Home, V720, and ix cam lines, with all versions listed as affected.
What the bugs enable
The advisory describes several distinct weaknesses. One flaw in the onboarding flow allows a replay of the confirm-then-bind process, which can silently move a device to an attacker-controlled account. Another issue exposes a persistent relay credential through an API without checking whether the requester is the real device owner, allowing credential theft and relay impersonation.
CISA also says Naxclow devices use a server-side relay credential that never rotates and is re-issued on boot. That means once the secret is exposed, access can remain valid for a long time, even after a reset or re-onboarding. A separate weakness comes from a hard-coded, platform-wide salt embedded in firmware images, which can be used to generate valid request signatures once recovered from any device. The advisory notes that the platform also uses plain HTTP for control-plane traffic, increasing the risk of forgery and interception.
Vendor response and impact
CISA says Naxclow did not respond to attempts to coordinate disclosure, and users are told to contact the vendor for more information. The overall picture is a platform with several architecture-level trust failures: weak device ownership checks, static secrets, and limited replay protection. That combination makes compromise potentially scalable rather than isolated.
Key points
- CISA says exploitation could let attackers impersonate devices, intercept traffic, and steal credentials at scale.
- The affected products include Naxclow Smart Doorbell X3, X Smart Home, V720, and ix cam, across all versions listed.
- One issue lets an attacker replay onboarding steps and reassign a device to another account.
- Another flaw exposes relay credentials without confirming the requester is the legitimate owner.
- CISA says Naxclow did not respond to coordination attempts.
If Naxclow responds and fixes the design issues, the platform could become much harder to spoof or hijack. Better ownership checks, rotating secrets, and stronger transport security would reduce the chance of large-scale device impersonation.
If the flaws stay unpatched, attackers could keep access even after owners reset devices or set them up again. The reusable credentials and weak request-signing design could also make interception and impersonation easier across many devices at once.



