CVE-2026-2065

A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Bluetooth Low Energy Interface. Performing a manipulation results in missing authentication. The attack can only be performed from the local network. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:flycatcher:smart_pixelator_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:flycatcher:smart_pixelator:2.0:*:*:*:*:*:*:*

History

05 Mar 2026, 20:52

Type Values Removed Values Added
First Time Flycatcher
Flycatcher smart Pixelator
Flycatcher smart Pixelator Firmware
References () https://github.com/davidrxchester/smart-pixelator-upload - () https://github.com/davidrxchester/smart-pixelator-upload - Not Applicable
References () https://github.com/davidrxchester/smart-pixelator-upload/blob/main/poc.py - () https://github.com/davidrxchester/smart-pixelator-upload/blob/main/poc.py - Product
References () https://vuldb.com/?ctiid.344632 - () https://vuldb.com/?ctiid.344632 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.344632 - () https://vuldb.com/?id.344632 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.745129 - () https://vuldb.com/?submit.745129 - Third Party Advisory, VDB Entry
CPE cpe:2.3:o:flycatcher:smart_pixelator_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:flycatcher:smart_pixelator:2.0:*:*:*:*:*:*:*
CWE CWE-862

06 Feb 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 20:16

Updated : 2026-03-05 20:52


NVD link : CVE-2026-2065

Mitre link : CVE-2026-2065

CVE.ORG link : CVE-2026-2065


JSON object : View

Products Affected

flycatcher

  • smart_pixelator
  • smart_pixelator_firmware
CWE
CWE-287

Improper Authentication

CWE-306

Missing Authentication for Critical Function

CWE-862

Missing Authorization