Work

CVE-2022-46640

Remote Code Execution
Unauthenticated
Application security

Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.

A bright pink sheet of paper used to wrap flowers curves in front of rich blue background

We found and responsibly disclosed vulnerabilities in the Nanoleaf desktop app. After an extensive research period we found several critical vulnerabilities in their desktop application to manage their IoT devices. The most severe vulnerability was an unauthenticated remote code execution vulnerability, which allowed an attacker to take over the device running the application by sending an network packet. Considering the possibly major impact of this vulnerability, we followed a very strict vulnerability disclosure protocol.

The vulnerability got dubbed as CVE-2022-46640 with a rating of 9.8/10 (critical) by NIST. The exact vector of the vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.