Work

CVE-2022-47758

Remote Code Execution
Unauthenticated
Application security

Nanoleaf firmware v7.1.1 and below is missing an SSL certificate, allowing attackers to execute arbitrary code via a DHCP hijacking attack.

A bright pink sheet of paper used to wrap flowers curves in front of rich blue background

We found and responsibly disclosed vulnerabilities in the Nanoleaf smart lamp firmware. We performed extensive research on their embedded devices and analyzed several attack surfaces. At the end of the research period, we managed to remotely take over devices by (locally) hijacking a communications channel used for debugging. The conclusion was that a malicious actor could redirect network traffic to hack arbitrary Nanoleaf lamps, regardless of any firewalls.

The vulnerability got allocated CVE-2022-47758.