Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data. (CVE-2026-21079)
A vulnerability in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept sensitive data transmitted without encryption. This issue arises from missing encryption of sensitive data during transmission, exposing it to interception by attackers in close network proximity.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2026-21079 affects Smart Switch versions before 3.7.72.6. It is caused by the absence of encryption for sensitive data during transmission, enabling attackers in adjacent network positions to intercept this data. The CVSS 4.0 vector indicates a high severity with low attack complexity but requires adjacent access and some privileges. No known exploits are reported in the wild, and the product is not a cloud service.
Potential Impact
Sensitive data transmitted by Smart Switch prior to version 3.7.72.6 can be intercepted by attackers positioned adjacent to the victim on the network. This compromises confidentiality of the data, potentially exposing private or sensitive information.
Mitigation Recommendations
Upgrade Smart Switch to version 3.7.72.6 or later where encryption of sensitive data during transmission is implemented. No other mitigation or temporary fixes are indicated. Patch status is not explicitly confirmed in the input data, so verify with the vendor advisory for the latest remediation guidance.
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data. (CVE-2026-21079)
Description
A vulnerability in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept sensitive data transmitted without encryption. This issue arises from missing encryption of sensitive data during transmission, exposing it to interception by attackers in close network proximity.
CVSS v4.0
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-21079 affects Smart Switch versions before 3.7.72.6. It is caused by the absence of encryption for sensitive data during transmission, enabling attackers in adjacent network positions to intercept this data. The CVSS 4.0 vector indicates a high severity with low attack complexity but requires adjacent access and some privileges. No known exploits are reported in the wild, and the product is not a cloud service.
Potential Impact
Sensitive data transmitted by Smart Switch prior to version 3.7.72.6 can be intercepted by attackers positioned adjacent to the victim on the network. This compromises confidentiality of the data, potentially exposing private or sensitive information.
Mitigation Recommendations
Upgrade Smart Switch to version 3.7.72.6 or later where encryption of sensitive data during transmission is implemented. No other mitigation or temporary fixes are indicated. Patch status is not explicitly confirmed in the input data, so verify with the vendor advisory for the latest remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8ch7-v647-mr2v
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-21079"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a79f0e0bf8831d539f620e7
Added to database: 08/10/2026, 15:40:16 UTC
Last enriched: 08/10/2026, 16:02:09 UTC
Last updated: 08/10/2026, 18:40:59 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.