Nanoleaf manufactures smart lighting products and control software, including light strips and desktop applications, with a narrow but specialized focus on networked LED fixtures and their management interfaces. The durable signal in disclosures centers on certificate validation, command-injection, and permission-assignment weaknesses, alongside resource-consumption issues that reflect the integration of network connectivity and firmware update mechanisms into consumer lighting hardware. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nanoleaf over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47758CRITICAL Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack. | Apr 27, 2023 | 9.8 | 34 | NO | NO |
CVE-2022-46640CRITICAL Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request. | Apr 18, 2023 | 9.8 | 34 | NO | NO |
CVE-2023-45955HIGH An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commands. | Oct 31, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-42189HIGH Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0 | Oct 10, 2023 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nanoleaf.
Media articles that mention a CVE ID that affects a product developed by Nanoleaf — matched by CVE ID, not by vendor name.