Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept for an SQLite FTS3/FTS4 information disclosure issue labeled CVE-2026-21004. It contains three files: an MIT LICENSE, a README describing the issue and usage, and a single Python exploit script, sqlite_fts_leak.py. The script uses Python's sqlite3 module to create an in-memory SQLite database, define an FTS4 virtual table named secrets, insert sample sensitive records, and then recover indexed content via repeated MATCH prefix queries. The exploit capability is blind data extraction rather than code execution. Its core logic is in guess_char(), which iterates over a candidate alphabet and submits MATCH expressions of the form "<known_prefix><candidate>*". If a row is returned, the candidate character is accepted and appended to the recovered prefix. Repeating this loop reconstructs secret content character-by-character. This demonstrates how observable MATCH behavior can leak whether indexed terms exist, enabling brute-force exfiltration from searchable FTS-backed data. There are no network callbacks, remote URLs, IPs, or external services in the code. The only notable endpoints/artifacts are the SQLite in-memory database (:memory:), the FTS4 virtual table creation statement, and the probing SQL query. The repository is not part of a known exploit framework and should be classified as a standalone PoC. It is a valid exploit demonstration for information disclosure, but not weaponized: it uses hardcoded sample data and does not include a generalized remote delivery mechanism.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.