CVE-2025-7202: Elgato Key Light
Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights.
Affected products
- Elgato Key Light: up to and including 1.0.3(218)
- Elgato Key Light Air: up to and including 1.0.3.220
- Elgato Key Light Mini: up to and including 1.0.4.239
- Elgato Key Light Neo: up to and including 1.0.4.206
- Elgato Light Strip: up to and including 1.0.4.231
- Elgato Light Strip Pro: up to and including 1.0.1.145
- Elgato Ring Light: up to and including 1.0.4.149
Published 2025-08-06. Last modified 2026-06-17.