CVE-2026-33268: Nanoleaf Lines unauthenticated firmware file store
Published Mar 25, 2026
·Updated
Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmware files on the device and consume storage resources. Fixed in 12.3.6.
Affected Software
1 affected component
Nanoleaf Nanoleaf Lines<12.3.6
Event History
Mar 25, 2026
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-33268?
CVE-2026-33268 is considered a high severity vulnerability due to the potential for remote, unauthenticated attackers to exploit it.
2
How do I fix CVE-2026-33268?
To fix CVE-2026-33268, upgrade the Nanoleaf Lines firmware to version 12.3.6 or later.
3
What impact does CVE-2026-33268 have on my device?
CVE-2026-33268 can lead to unauthorized firmware file uploads, potentially resulting in storage resource consumption and device malfunction.
4
Which versions of Nanoleaf Lines are affected by CVE-2026-33268?
CVE-2026-33268 affects versions of Nanoleaf Lines prior to 12.3.6.
5
Is authentication required for firmware uploads in CVE-2026-33268?
No, CVE-2026-33268 allows unauthenticated firmware uploads, making it vulnerable to exploitation.