Check Your Switch
Guide Information
Check if your Switch is unpatched and if you can run CFW without a modchip being fitted.
- Fusée Gelée Explained
- Serial Checker
- Switch Variants
- 20+ Minutes
Background
The Nintendo Switch powered by the Nvidia Tegra X1 chip was released in 2017. By early 2018 the Fusée Gelée (“frozen rocket” in French) exploit was found. Fusée Gelée is a coldboot vulnerability that allows complete unauthenticated arbitrary code execution from the bootROM. It is a non persistent exploit which needs to be used after powering off or booting the device normally without custom firmware (CFW).
Coldboot exploits grant hackers full system takeover so they can load their own code on start up before any operating system has been loaded, any boot code has been executed, and most importantly, any security measures have been enabled.
The Fusée Gelée vulnerability lies within the Nvidia Tegra X1’s USB recovery mode. This mode circumvents the lock-out operations that usually protect the chip’s bootROM.
If you want a more in-depth look at the Fusée Gelée exploit, you can click the link below.
Any Switch that is able to use the Fusée Gelée exploit are referred to as ‘Unpatched’. These are the considered more desirable (from a purely hacking standpoint) because you don’t need to pay a professional to solder in an expensive modchip to run CFW. We can identify if a Switch is Unpatched by checking the serial number against a database.
Check Your Serial
-
XAW1
-
Unpatched:
XAW10074000000 & Below
-
Possibly Patched:
XAW10075000000-XAW10120000000
-
Definitely Patched:
XAW10120000000 & Above
-
XAW4
-
Unpatched:
XAW40011000000 & Below
-
Possibly Patched:
XAW40011000000-XAW40012000000
-
Definitely Patched:
XAW4001200000 & Above
-
XAW7
-
Unpatched:
XAW70017500000 & Below
-
Possibly Patched:
XAW70017500000-XAW70030000000
-
Definitely Patched:
XAW70030000000 & Above
-
XAJ1
-
Unpatched:
XAJ10020000000 & Below
-
Possibly Patched:
XAJ10020000000-XAJ10030000000
-
Definitely Patched:
XAJ10030000000 & Above
-
XAJ4
-
Unpatched:
XAJ40046000000 & Below
-
Possibly Patched:
XAJ40046000000-XAJ40083000000
-
Definitely Patched:
XAJ40083000000 & Above
-
XAJ7
-
Unpatched:
XAJ70040000000 & Below
-
Possibly Patched:
XAJ70040000000-XAJ70050000000
-
Definitely Patched:
XAJ70050000000 & Above
-
XAW9
-
Possibly Patched:
Nintendo refurbished Consoles All Possibly Patched
-
XAK
-
Possibly Patched:
No Information Available for serials with this prefix
-
XKW & XKJ
-
Definitely Patched:
You're out of luck, all these serials Definitely Patched
- If you are still unsure you can click the link below.
- If your Switch is Possibly Patched, click the link below and follow the guide to inject a payload.
Switch Variants
Unpatched Erista
All serials listed as Unpatched are the original 2017 Switch. They are exploitable via the Fusée Gelée exploit (explained above). Once in RCM, you can inject payloads to boot into CFW and homebrew applications. Unpatched Erista came in a mostly white box.
Patched Erista
All serials listed as Possibly Patched are a mixture of Unpatched and Patched Erista. In mid 2018 Nintendo were patching the Switch to combat the Fusée Gelée exploit. They cannot run CFW without a modchip installed, unless on Firmware 4.1.0. or lower. Patched Erista came in a mostly white box.
Mariko
All Switch models listed as Definitely Patched are Patched Erista or Mariko systems. Mariko are the "New Switch" released in 2019. While the battery life on these systems is better they cannot run CFW without a modchip installed. The Mariko came in an all red box.
Lite
Also Mariko systems. All Switch Lites are Definitely Patched they cannot run CFW without a modchip installed.
OLED
All Switch OLED systems are Definitely Patched. They cannot run CFW without a modchip installed.