CVE-2026-33268
Awaiting Analysis
Awaiting Analysis - Queue
Unauthenticated Firmware Upload in Nanoleaf Lines Causes Resource Exhaustion
Publication date: 2026-03-25
Last updated on: 2026-03-25
Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
Description
Description
Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmware files on the device and consume storage resources. Fixed in 12.3.6.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nanoleaf | lines | 12.3.6 |
| nanoleaf | lines | to 12.3.6 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |