{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-82079","assignerOrgId":"60e0823a-f1a8-4923-bd51-812de398c42c","state":"PUBLISHED","assignerShortName":"Nintendo","dateReserved":"2026-08-28T00:46:53.480Z","datePublished":"2026-09-10T05:13:33.030Z","dateUpdated":"2026-09-11T03:56:09.883Z"},"containers":{"cna":{"providerMetadata":{"orgId":"60e0823a-f1a8-4923-bd51-812de398c42c","shortName":"Nintendo","dateUpdated":"2026-09-11T00:57:53.834Z"},"title":"Potential Leakage of Nintendo Switch System Information Through a Proximity-Based Remote Attack","datePublic":"2026-09-10T05:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-121","description":"CWE-121 Stack-based buffer overflow","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-100","descriptions":[{"lang":"en","value":"CAPEC-100 Overflow Buffers"}]}],"affected":[{"vendor":"Nintendo","product":"Nintendo Switch","versions":[{"status":"affected","version":"0","lessThan":"23.0.0","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic.\nThis issue affects Nintendo Switch: before 23.0.0.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p><span>A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic.<br></span><span>This issue affects Nintendo Switch: before 23.0.0.</span></p>"}]}],"references":[{"url":"https://www.nintendo.com/security-advisories/en/index.html"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"LOW","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":7,"vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"}}],"workarounds":[{"lang":"en","value":"If you cannot update to the latest system version right away, please note the following when using the system.\n\n\n\n\n\n  *  When using the \"Send to Smartphone\" feature in Album or when using a kart in Mario Kart Live: Home Circuit, please ensure that the QR code displayed on the console screen (or on the TV screen) cannot be viewed or scanned by third parties.\n  *  Please refrain from using the \"Send to Smartphone\" feature in Album with a smartphone other than your own, and from using a kart other than your own in Mario Kart Live: Home Circuit.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>If you cannot update to the latest system version right away, please note the following when using the system.</p><p></p><ul><li><span>When using the \"Send to Smartphone\" feature in Album or when using a kart in Mario Kart Live: Home Circuit, please ensure that the QR code displayed on the console screen (or on the TV screen) cannot be viewed or scanned by third parties.</span></li><li><span>Please refrain from using the \"Send to Smartphone\" feature in Album with a smartphone other than your own, and from using a kart other than your own in Mario Kart Live: Home Circuit.</span></li></ul><p></p>"}]}],"solutions":[{"lang":"en","value":"Perform System Update 23.0.0.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>Perform System Update 23.0.0.</p>"}]}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":8.4,"attackVector":"LOCAL","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-09-10T00:00:00+00:00","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3","id":"CVE-2026-82079"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-11T03:56:09.883Z"}}]}}