Impact
A stack‑based buffer overflow in the Nintendo Switch local wireless networking stack permits an attacker within wireless range to deliver crafted packets that overflow for return‑oriented programming, allowing the attacker to execute arbitrary code on the console. This weakness falls compromise system confidentiality, integrity and availability if left unpatched.
Affected Systems
Nintendo Switch consoles running firmware versions prior to 23.0.0 are vulnerable. The issue is specific to the local wireless networking feature used by applications such as the Album Send to Smartphone function and the Send to Smartphone feature in Mario Kart Live: Home Circuit. Users should verify their console firmware version to determine if the patch is required.
Risk and Exploitability
Because the vulnerability requires proximity, an adversary must be within beyond that exists. The unpatched state, with a CVSS score of 7, indicates a high‑impact remote code execution path. The EPSS score is < 1%, suggesting a very low probability of exploitation, but the risk remains due to the severe impact. The CVE has not been recorded in the CISA KEV catalogue, but its nature suggests that it could be abused by determined actors. The official remedy is a0; if that is not possible, limiting exposure by disabling or avoiding the affected features reduces risk.
OpenCVE Enrichment