CWE-639 Authorization bypass through User-Controlled key in Naxclow Smart Doorbell X3 (CVE-2026-42947)
CVE-2026-42947 is a high-severity authorization bypass vulnerability in the Naxclow Smart Doorbell X3. The flaw exists in the onboarding workflow, allowing an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. The affected endpoints validate request signatures but do not verify legitimate ownership, enabling attackers with any account to take over devices without user interaction while the device remains online and unaware.
AI Analysis
Technical Summary
This vulnerability in Naxclow Smart Doorbell X3 involves an authorization bypass (CWE-639) where the onboarding workflow's confirm-then-bind sequence can be replayed by an attacker. Although request signatures are validated, the system fails to confirm that the requester legitimately owns the device. Consequently, an attacker with any account can silently reassign the device to themselves without alerting the current owner or requiring user interaction. This affects all versions of the product. The CVSS 4.0 base score is 8.7, reflecting network attack vector, low complexity, no user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
An attacker with any account can take over a Naxclow Smart Doorbell X3 device by replaying the confirm-then-bind sequence, effectively reassigning the device to their account without the legitimate owner's knowledge or interaction. This compromises device ownership and control, potentially allowing unauthorized access to device functions and data.
Mitigation Recommendations
No patch or official fix is currently available for this vulnerability. Users and administrators should monitor the vendor's advisory channels for updates. Until a fix is released, restricting account access and monitoring device onboarding activities may help reduce risk, but no definitive mitigation is confirmed.
CWE-639 Authorization bypass through User-Controlled key in Naxclow Smart Doorbell X3 (CVE-2026-42947)
Description
CVE-2026-42947 is a high-severity authorization bypass vulnerability in the Naxclow Smart Doorbell X3. The flaw exists in the onboarding workflow, allowing an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. The affected endpoints validate request signatures but do not verify legitimate ownership, enabling attackers with any account to take over devices without user interaction while the device remains online and unaware.
CVSS v4.0
Score 8.7high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Naxclow Smart Doorbell X3 involves an authorization bypass (CWE-639) where the onboarding workflow's confirm-then-bind sequence can be replayed by an attacker. Although request signatures are validated, the system fails to confirm that the requester legitimately owns the device. Consequently, an attacker with any account can silently reassign the device to themselves without alerting the current owner or requiring user interaction. This affects all versions of the product. The CVSS 4.0 base score is 8.7, reflecting network attack vector, low complexity, no user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
An attacker with any account can take over a Naxclow Smart Doorbell X3 device by replaying the confirm-then-bind sequence, effectively reassigning the device to their account without the legitimate owner's knowledge or interaction. This compromises device ownership and control, potentially allowing unauthorized access to device functions and data.
Mitigation Recommendations
No patch or official fix is currently available for this vulnerability. Users and administrators should monitor the vendor's advisory channels for updates. Until a fix is released, restricting account access and monitoring device onboarding activities may help reduce risk, but no definitive mitigation is confirmed.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- CISA
- Advisory Id
- ICSA-26-162-02
- Cve Count
- 7
- Additional Cves
- ["CVE-2026-50108","CVE-2026-50101","CVE-2026-28742","CVE-2026-42932","CVE-2026-50244","CVE-2026-50099"]
- Cvss Version
- null
Threat ID: 6a2bea1be617e2d834589bf4
Added to database: 06/12/2026, 11:14:35 UTC
Last enriched: 06/19/2026, 16:56:22 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 88
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.