Executive brief
The Avation Light Engine Pro, a device used for lighting control in commercial facilities, contains a critical security flaw where its configuration and control interface is accessible without any password or authentication. This allows any individual with network access to the device to take full control of its operations, potentially leading to unauthorized lighting changes, service disruptions, or further network intrusion. Because the vendor has not yet provided a fix, organizations should ensure these devices are isolated from the internet and protected behind firewalls.
Technical details
The Avation Light Engine Pro suffers from a missing authentication for critical function vulnerability (CWE-306). The device's configuration and control interfaces are exposed to the network without any access control mechanisms. A remote, unauthenticated attacker can exploit this by connecting to the device over the network to modify settings or issue commands. Successful exploitation grants the attacker full control over the device's functionality. As of the advisory date, the vendor has not responded to coordination efforts, and no official patch is available; users are advised to implement network segmentation and VPNs to mitigate risk.
Affected products
- Avation Light Engine Pro All versions
Timeline
- 2026-02-03: advisory: Initial publication of ICSA-26-034-02 by CISA
- 2026-02-03: disclosed: Vulnerability published in NVD