Naxclow IoT Platform
This CISA advisory details a critical vulnerability in the Naxclow IoT Platform, specifically affecting versions of the Smart Doorbell X3, X Smart Home, V720, and ix cam devices. The flaw allows an attacker to impersonate devices, intercept communications, and harvest credentials due to a lack of proper authorization checks and a predictable device identifier scheme. This poses a significant risk to devices and their associated data, particularly within commercial facilities.
The Naxclow IoT Platform is vulnerable to a series of weaknesses that enable unauthorized access and control. Specifically, the platform's onboarding workflow lacks proper validation, allowing an attacker to replay a confirm-then-bind sequence to reassign devices to an arbitrary account. Furthermore, the system utilizes a persistent, non-rotating credential for each device, making it susceptible to credential theft. The predictable device identifiers and the exposure of the high-water mark further exacerbate the risk, allowing for enumeration of the entire device fleet. The lack of response from Naxclow to CISA's coordination efforts adds to the urgency of this situation. The vulnerability impacts devices deployed worldwide, primarily within commercial facilities, and highlights the importance of robust security practices in IoT device management.