Nintendo's vulnerability profile centers on a small portfolio of Wi-Fi network adapters and wireless communication devices, which are embedded in gaming consoles and peripherals where firmware updates may propagate slowly or inconsistently. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through memory-safety and command-injection weakness classes such as classic buffer overflows, OS command injection, and out-of-bounds writes that are characteristic of embedded network firmware. Defenders should prioritize patching affected wireless devices and inventory long-lived gaming hardware, as remediation timelines for consumer electronics can extend substantially; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nintendo Co., Ltd. over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47949CRITICAL The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet | Dec 24, 2022 | 9.8 | 37 | NO | NO |
CVE-2023-45887CRITICAL DS Wireless Communication (DWC) with DWC_VERSION_3 and DWC_VERSION_11 allows remote attackers to execute arbitrary code on a game-playing client's machine via a modified GPCM messa | Dec 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-13109CRITICAL Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted packet data to the built-in modem because 0x800b3e94 (aka t | May 16, 2020 | 9.8 | 29 | NO | NO |
CVE-2023-35856CRITICAL A buffer overflow in Nintendo Mario Kart Wii RMCP01, RMCE01, RMCJ01, and RMCK01 can be exploited by a game client to execute arbitrary code on a client's machine via a crafted pack | Jun 19, 2023 | 9.8 | 27 | NO | NO |
CVE-2022-36293HIGH Buffer overflow vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary code via unspecified v | Aug 16, 2022 | 7.2 | 25 | NO | NO |
CVE-2022-36381HIGH OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary OS commands via u | Aug 16, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-3216HIGH A vulnerability has been found in Nintendo Game Boy Color and classified as problematic. This vulnerability affects unknown code of the component Mobile Adapter GB. The manipulatio | Sep 14, 2022 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nintendo Co., Ltd..
Media articles that mention a CVE ID that affects a product developed by Nintendo Co., Ltd. — matched by CVE ID, not by vendor name.