PT-2023-15476 · Nanoleaf · Nanoleaf

·

CVE-2022-47758

·

Published

2023-04-27

·

Updated

2025-01-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nanoleaf firmware versions prior to 7.1.1
Description The issue is related to missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack. This affects IoT smart lights, enabling unauthenticated remote code execution.
Recommendations For versions prior to 7.1.1, update to a version that includes TLS verification to prevent arbitrary code execution via DNS hijacking attacks. As a temporary workaround, consider restricting access to the device until a patch is available. Avoid using the device in untrusted networks to minimize the risk of exploitation.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-47758

Affected Products

Nanoleaf