Nexx smart garage door openers have been proven to contain shared, unsecured authentication credentials that can be used to access and control the API. This includes opening doors.
Recently, a security researcher discovered that Nexx "smart" garage door openers are vulnerable to abuse at the API layer. Here's a summary of what was found, along with a few key citations.
CISA warns owners of Nexx products that attackers could access sensitive information, execute API requests, or hijack their devices.
Unfortunately, the manufacturer has not responded to multiple disclosure attempts, or proposed collaboration from security organizations to help with remediation. The best recommendations at this point are to either disable the devices, remove their Internet connectivity (rendering them less "smart" by definition), or only connecting via VPN.