Skip to main content

Vendor archive

nanoleaf CVEs

Beta · best-effort

4 CVEs tagged to vendor nanoleaf2 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2022-47758

Published Apr 27, 2023

Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-46640

Published Apr 18, 2023

Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1