Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
http://nanoleaf.com | product |
https://pwning.tech/cve-2022-47758 | third party advisory exploit technical description |
https://pwning.tech/cve-2022-47758/ |