Description
A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic.
This issue affects Nintendo Switch: before 23.0.0.
Published: 2026-09-10
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

A stack‑based buffer overflow in the Nintendo Switch local wireless networking stack permits an attacker within wireless range to deliver crafted packets that overflow for return‑oriented programming, allowing the attacker to execute arbitrary code on the console. This weakness falls compromise system confidentiality, integrity and availability if left unpatched.

Affected Systems

Nintendo Switch consoles running firmware versions prior to 23.0.0 are vulnerable. The issue is specific to the local wireless networking feature used by applications such as the Album Send to Smartphone function and the Send to Smartphone feature in Mario Kart Live: Home Circuit. Users should verify their console firmware version to determine if the patch is required.

Risk and Exploitability

Because the vulnerability requires proximity, an adversary must be within beyond that exists. The unpatched state, with a CVSS score of 7, indicates a high‑impact remote code execution path. The EPSS score is < 1%, suggesting a very low probability of exploitation, but the risk remains due to the severe impact. The CVE has not been recorded in the CISA KEV catalogue, but its nature suggests that it could be abused by determined actors. The official remedy is a0; if that is not possible, limiting exposure by disabling or avoiding the affected features reduces risk.

Generated by OpenCVE AI on September 11, 2026 at 03:33 UTC.

Remediation

Vendor Solution

Perform System Update 23.0.0.


Vendor Workaround

If you cannot update to the latest system version right away, please note the following when using the system. * When using the "Send to Smartphone" feature in Album or when using a kart in Mario Kart Live: Home Circuit, please ensure that the QR code displayed on the console screen (or on the TV screen) cannot be viewed or scanned by third parties. * Please refrain from using the "Send to Smartphone" feature in Album with a smartphone other than your own, and from using a kart other than your own in Mario Kart Live: Home Circuit.


OpenCVE Recommended Actions

  • Apply the system update to firmware 23.0.0 immediately.
  • If a firmware update cannot be performed right away, avoid using the Send to Smartphone feature in the Album or playing Mario Kart Live: Home Circuit with non‑owner devices and ensure QR codes are not viewable by third parties.
  • Disable or refrain from using the local wireless networking functions that rely on the vulnerable stack, such as data transfer features in games or the phone‑screen QR code display, until a patch is applied.

Generated by OpenCVE AI on September 11, 2026 at 03:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Nintendo
Nintendo nintendo Switch
Vendors & Products Nintendo
Nintendo nintendo Switch

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic. This issue affects Nintendo Switch: before 23.0.0.
Title Potential Leakage of Nintendo Switch System Information Through a Proximity-Based Remote Attack
Weaknesses CWE-121
References

Subscriptions

Nintendo Nintendo Switch
cve-icon MITRE

Status: PUBLISHED

Assigner: Nintendo

Published:

Updated: 2026-09-11T03:56:09.883Z

Reserved: 2026-08-28T00:46:53.480Z

Link: CVE-2026-82079

cve-icon Vulnrichment

Updated: 2026-09-10T14:55:59.643Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T06:17:06.330

Modified: 2026-09-11T04:17:59.633

Link: CVE-2026-82079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T03:45:19Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow