Skip to content
COOEY

FAIL › dossier

nanoleaf

VENDOR

· dossier confidence 0%

Nanoleaf is a smart home lighting vendor with a critical security history of unpatched RCE vulnerabilities in its firmware and desktop applications. Its track record of missing TLS verification and command injection flaws makes it a high-risk vendor for defense-industrial-base procurement.

PROFILE
CategoryIoT / Smart HomeWhat they doNanoleaf develops and sells smart lighting products and related software for consumers.
SECURITY POSTURE

Nanoleaf has a poor security track record, with multiple critical remote code execution (RCE) vulnerabilities in its firmware and desktop applications that were exploited via DNS hijacking and command injection.

Notable failures
  • CVE-2022-47758: Firmware RCE via DNS hijacking
  • CVE-2022-46640: Desktop app command injection
Patterns: repeated unpatched edge-device RCEs; missing TLS verification in firmware; command injection in companion apps
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2023-04-27 CVE-2022-47758 critical Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
2023-04-18 CVE-2022-46640 critical Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.
Open questions: Exact founding year and HQ location require external verification as they are not in the provided evidence. · Current employee count and ownership structure are not in the provided evidence.
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-22 04:17:35.742204+00:00