CVE-2025-7202: Elgato Key Light

Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights.

Affected products

  • Elgato Key Light: up to and including 1.0.3(218)
  • Elgato Key Light Air: up to and including 1.0.3.220
  • Elgato Key Light Mini: up to and including 1.0.4.239
  • Elgato Key Light Neo: up to and including 1.0.4.206
  • Elgato Light Strip: up to and including 1.0.4.231
  • Elgato Light Strip Pro: up to and including 1.0.1.145
  • Elgato Ring Light: up to and including 1.0.4.149

Published 2025-08-06. Last modified 2026-06-17.