In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade LizardByte/Sunshine
to version 2025.118.151840 or higher.
Affected versions of this package are vulnerable to Authentication Bypass by Primary Weakness in nvhttp.cpp
, due to improper request order enforcement during pairing. An attacker in a MitM position can record, modify, and play back a legitimate pairing attempt to gain access to the vulnerable server. Once observed, the legitimate client's PIN may be brute forced offline and used to validate the attacker's certificate. A remote attacker may also cause a crash by abusing the improper request ordering.