NintendoCVEs & Vulnerabilities

7 CVEs affecting Nintendo products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

mario kart wii 4ds wireless communication 2mario kart 8 2wi-fi network adaptor wap 001 2wi-fi network adaptor wap 001 firmware 2animal crossing\ 1splatoon 1splatoon 2 1
CVE-2023-45887CRITICAL

DS Wireless Communication (DWC) with DWC_VERSION_3 and DWC_VERSION_11 allows remote attackers to execute arbitrary code on a game-playing client's machine via a modified GPCM message.

20 Dec 2023
9.8
CVSS
CVE-2023-35856CRITICAL

A buffer overflow in Nintendo Mario Kart Wii RMCP01, RMCE01, RMCJ01, and RMCK01 can be exploited by a game client to execute arbitrary code on a client's machine via a crafted packet.

19 Jun 2023
9.8
CVSS
CVE-2022-47949CRITICAL

The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022.

25 Dec 2022
9.8
CVSS
CVE-2022-3216HIGH

A vulnerability has been found in Nintendo Game Boy Color and classified as problematic. This vulnerability affects unknown code of the component Mobile Adapter GB. The manipulation leads to memory corruption. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-208606 is the identifier assigned to this vulnerability.

14 Sep 2022
8.8
CVSS
CVE-2022-36381HIGH

OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.

16 Aug 2022
7.2
CVSS
CVE-2022-36293HIGH

Buffer overflow vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary code via unspecified vectors.

16 Aug 2022
7.2
CVSS
CVE-2020-13109CRITICAL

Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted packet data to the built-in modem because 0x800b3e94 (aka the IF subcommand to top-level command 7) has a stack-based buffer overflow.

16 May 2020
9.8
CVSS
← PrevPage 1 / 1Next →
Nintendo CVEs & Vulnerabilities — 7 Tracked