CVE-2026-33268
Awaiting Analysis Awaiting Analysis - Queue
Unauthenticated Firmware Upload in Nanoleaf Lines Causes Resource Exhaustion

Publication date: 2026-03-25

Last updated on: 2026-03-25

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description
Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmware files on the device and consume storage resources. Fixed in 12.3.6.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-25
Last Modified
2026-03-25
Generated
2026-05-07
AI Q&A
2026-03-25
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
nanoleaf lines 12.3.6
nanoleaf lines to 12.3.6 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :

An attacker exploiting this vulnerability can upload firmware files without authentication, which can lead to consumption of the device's storage resources.

This could potentially cause denial of service conditions by filling up storage, impacting device availability and functionality.

The CVSS score indicates a moderate severity with impact on integrity and availability.


Can you explain this vulnerability to me?

The vulnerability in Nanoleaf Lines version 12.3.2 is due to the device not authenticating firmware file uploads. This means that a remote attacker who is not authenticated can upload firmware files to the device.

Because the device does not verify the legitimacy of the firmware files being uploaded, an attacker can exploit this to upload arbitrary firmware files.

This vulnerability was fixed in version 12.3.6.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, you should upgrade your Nanoleaf Lines device firmware to version 12.3.6 or later, where the issue has been fixed.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart