CVE-2026-0842

MEDIUM

Flycatcher Toys smART Sketcher <2.0 - Missing Authentication

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-0842. PoCs published by davidrxchester.

AI-analyzed exploit summary This repository contains a functional Python script that exploits CVE-2026-0842, a missing authentication vulnerability in the smART Sketcher 2.0 Bluetooth interface. The exploit allows unauthenticated image uploads to the device via BLE without pairing or notification.

Description

A flaw has been found in Flycatcher Toys smART Sketcher up to 2.0. This affects an unknown part of the component Bluetooth Low Energy Interface. This manipulation causes missing authentication. The attack can only be done within the local network. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploits (1)

nomisec WORKING POC 3 stars
by davidrxchester · poc
https://github.com/davidrxchester/smart-sketcher-upload

This repository contains a functional Python script that exploits CVE-2026-0842, a missing authentication vulnerability in the smART Sketcher 2.0 Bluetooth interface. The exploit allows unauthenticated image uploads to the device via BLE without pairing or notification.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: smART Sketcher 2.0
No auth needed
Prerequisites: Bluetooth connectivity to the target device · Python environment with bleak and pillow libraries
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.340442
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.340442
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.729134

Scores

CVSS v3 6.3
EPSS 0.0036
EPSS Percentile 27.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-287 CWE-306
Status published
Products (1)
Flycatcher Toys/smART Sketcher 2.0
Published Jan 11, 2026
Tracked Since Feb 18, 2026