Configuration Exposure in WLED LED Controller by Aircoookie
CVE-2026-71264
8.2HIGH
What is CVE-2026-71264?
The WLED LED controller has a serious flaw in its GET /json/cfg endpoint, where it does not require a settings-PIN check. This vulnerability allows any unauthenticated client on the local network to access the device's sensitive configuration details, including network settings, hardware information, and LED setup. Additionally, once a client submits the correct settings-PIN via a POST request, that permission lasts across all clients, enabling them to make configuration changes such as OTA firmware updates and factory resets until the device is rebooted. This creates significant security risks for users, exposing their devices to unauthorized modifications.
Affected Version(s)
WLED 0
