Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23813 | A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights. |
| Link | Providers |
|---|---|
| https://www.toreon.com/flashing-your-lights-cve-2025-7202/ |
|
Thu, 07 Aug 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elgato
Elgato key Light Elgato light Strip Elgato ring Light |
|
| Vendors & Products |
Elgato
Elgato key Light Elgato light Strip Elgato ring Light |
Wed, 06 Aug 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 Aug 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights. | |
| Title | Cross-Site Request Forgery (CSRF) allowed remote control of Elgato Key Lights | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Toreon
Published:
Updated: 2025-08-06T20:23:30.776Z
Reserved: 2025-07-07T09:57:43.476Z
Link: CVE-2025-7202
Updated: 2025-08-06T20:23:27.365Z
Status : Deferred
Published: 2025-08-06T09:15:27.950
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-7202
No data.
OpenCVE Enrichment
Updated: 2025-08-06T15:12:36Z
EUVD