Skip to main content

Threats Tagged 'cve-2026-28742'

View all threats tagged with 'cve-2026-28742'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-28742

Threats Tagged 'cve-2026-28742'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-42947 is a high-severity authorization bypass vulnerability in the Naxclow Smart Doorbell X3. The flaw exists in the onboarding workflow, allowing an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. The affected endpoints validate request signatures but do not verify legitimate ownership, enabling attackers with any account to take over devices without user interaction while the device remains online and unaware.

Join the discussion

Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any device, an attacker can generate valid signatures for arbitrary device or account operations due to the absence of per-device keys, server-side nonce tracking, or replay protections. Combined with the system’s use of plain HTTP for control-plane traffic, the construction enables broad request forgery and impersonation across the platform.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-28742
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses