CVE-2022-47758: Nanoleaf Firmware

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.

Affected products

  • Nanoleaf Nanoleaf Firmware: version 7.1.1 only

Published 2023-04-27. Last modified 2026-07-09.