CVE-2026-33268
Unauthenticated Firmware Upload in Nanoleaf Lines Causes Resource Exhaustion
Publication date: 2026-03-25
Last updated on: 2026-03-25
Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nanoleaf | lines | 12.3.6 |
| nanoleaf | lines | to 12.3.6 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can upload firmware files without authentication, which can lead to consumption of the device's storage resources.
This could potentially cause denial of service conditions by filling up storage, impacting device availability and functionality.
The CVSS score indicates a moderate severity with impact on integrity and availability.
Can you explain this vulnerability to me?
The vulnerability in Nanoleaf Lines version 12.3.2 is due to the device not authenticating firmware file uploads. This means that a remote attacker who is not authenticated can upload firmware files to the device.
Because the device does not verify the legitimacy of the firmware files being uploaded, an attacker can exploit this to upload arbitrary firmware files.
This vulnerability was fixed in version 12.3.6.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, you should upgrade your Nanoleaf Lines device firmware to version 12.3.6 or later, where the issue has been fixed.