Getnexx manufactures a series of network appliances (NXAL-100, NXG-100B, NXG-200) where disclosed vulnerabilities center on authentication and access-control weaknesses, including user-controlled authorization keys, hard-coded credentials, and improper authentication mechanisms. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getnexx over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1748CRITICAL The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware coul | Apr 4, 2023 | 10.0 | 30 | NO | NO |
CVE-2023-1750HIGH The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could retrieve device history, set devi | Apr 4, 2023 | 7.1 | 23 | NO | NO |
CVE-2023-1749MEDIUM The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could send API requests that the affect | Apr 4, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-1751MEDIUM The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to ass | Apr 4, 2023 | 5.3 | 19 | NO | NO |
CVE-2023-1752MEDIUM The listed versions of Nexx Smart Home devices could allow any user to register an already registered alarm or associated device with only the device’s MAC address. | Apr 4, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getnexx.
Media articles that mention a CVE ID that affects a product developed by Getnexx — matched by CVE ID, not by vendor name.