CVE-2026-33268 PUBLISHED

Nanoleaf Lines unauthenticated firmware file store

Assigner: cisa-cg
Reserved: 18.03.2026 Published: 25.03.2026 Updated: 25.03.2026

Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmware files on the device and consume storage resources. Fixed in 12.3.6.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Nanoleaf
Product Lines
Versions Default: unknown
  • affected from 12.3.2 to 12.3.6 (excl.)
  • Version 12.3.6 is unaffected

Credits

  • Souvik Kandar

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE