Description
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
In plain language
AI Low urgencyIf your business uses Smart Switch versions earlier than 3.7.72.6, a nearby attacker could read sensitive information without needing an account—so you should update.
Improper input validation (CWE-20) in Smart Switch prior to 3.7.72.6 can allow adjacent attackers to access sensitive data through a network-reachable pathway with no authentication required.
What to do now
- Check whether your systems are running Smart Switch and confirm the installed version is earlier than 3.7.72.6.
- If it’s earlier, upgrade Smart Switch to 3.7.72.6 (or later).
- After updating, verify Smart Switch launches normally and that your device connections still work as expected.
CVSS Vector Breakdown
AV:AAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-21083 and every CVE in our database. Create a free account — no credit card required.
Create Free Account