Smart Switch
Vendor:
First CVE: Jun 4, 2025 · Active for 1 year
13
Total CVEs
More Total CVEs than 91% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Smart Switch over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 4, 2025
13 months ago
Most Recent CVE
Mar 16, 2026
131 days ago
CVE Severity & Scoring
Smart Switch13 CVEs
69%
15%
15%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (30.8%)
Network5 (38.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (30.8%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (69.2%)
Unknown0 (0.0%)
Required4 (30.8%)
Privileges Required
Low1 (7.7%)
High0 (0.0%)
None12 (92.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-20998CRITICAL Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication. | Mar 16, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-20997CRITICAL Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication. | Mar 16, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-21062HIGH Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required | Oct 10, 2025 | 7.8 | 26 | NO | NO |
CVE-2026-20999HIGH Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions. | Mar 16, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-21078MEDIUM Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to access backup data from applications. | Nov 5, 2025 | 6.5 | 24 | NO | NO |
CVE-2025-21064MEDIUM Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data. | Oct 10, 2025 | 6.5 | 24 | NO | NO |
CVE-2026-21005MEDIUM Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege. | Mar 16, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-21004MEDIUM Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service. | Mar 16, 2026 | 6.5 | 21 | NO | NO |
CVE-2025-21061MEDIUM Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering th | Oct 10, 2025 | 5.5 | 21 | NO | NO |
CVE-2025-21060MEDIUM Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required fo | Oct 10, 2025 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Smart Switch
Top CWEs
Versions
No cataloged versions.