CVE Database
/

CVE-2025-7202

Back to search

CVE-2025-7202

Published: Aug 6, 2025

Modified: Aug 6, 2025

PUBLISHED

Description

A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights.

VendorProductVersions

Elgato

Key Light

affected
0 - <= 1.0.3(218)

Elgato

Key Light Air

affected
0 - <= 1.0.3.220

Elgato

Key Light Mini

affected
0 - <= 1.0.4.239

Elgato

Key Light Neo

affected
0 - <= 1.0.4.206

Elgato

Ring Light

affected
0 - <= 1.0.4.149

Elgato

Light Strip

affected
0 - <= 1.0.4.231

Elgato

Light Strip Pro

affected
0 - <= 1.0.1.145

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now