Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 26 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nanoleaf
Nanoleaf lines |
|
| Vendors & Products |
Nanoleaf
Nanoleaf lines |
Wed, 25 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 25 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmware files on the device and consume storage resources. Fixed in 12.3.6. | |
| Title | Nanoleaf Lines unauthenticated firmware file store | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-03-25T15:53:45.320Z
Reserved: 2026-03-18T15:41:17.786Z
Link: CVE-2026-33268
Updated: 2026-03-25T14:50:50.928Z
Status : Awaiting Analysis
Published: 2026-03-25T15:16:48.280
Modified: 2026-03-25T16:16:21.793
Link: CVE-2026-33268
No data.
OpenCVE Enrichment
Updated: 2026-03-26T11:43:04Z