Impact
Naxclow devices use a server‑side, per‑device relay credential that never rotates and is re‑issued on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it can maintain persistent access to the device’s relay channel, enabling long‑term impersonation or interception even after factory resets or re‑onboarding.
Affected Systems
The affected devices are the Naxclow Smart Doorbell X3, V720, X Smart Home, and ix cam, all of which rely on the same unrevolving relay credential mechanism.
Risk and Exploitability
The CVSS score of 9.2 denotes a severe risk, yet the EPSS score is not available, leaving the precise exploitation likelihood uncertain. The vulnerability is not listed in KEV, but the lack of a public fix and the ability to persist access even after resets sustain a high threat posture. Likely attack vectors include any exposure path that discloses the credential, such as exploits of insecure firmware update channels, physical access, or network traffic interception. Once compromised, the attacker can impersonate the device or intercept communications indefinitely.
OpenCVE Enrichment