go to Center block
Upper block

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Lightstar|SmartIT Desktop Manager - 4 Vulnerabilities

TVN ID TVN-202609001
CVE ID CVE-2026-85146, CVE-2026-85147, CVE-2026-85148, CVE-2026-85149
CVSS 【CVE-2026-85146】
9.3 (Critical) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
9.8 (Critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

【CVE-2026-85147】
8.7 (High) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

【CVE-2026-85148】
9.3 (Critical) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
9.8 (Critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

【CVE-2026-85149】
6.9 (Medium) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
5.3 (Medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products SmartIT Desktop Manager version 10 and earlier
Description 【CVE-2026-85146(Use of Hard-coded Credentials)】
Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.

【CVE-2026-85147(Use of Hard-coded Credentials)】
Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.

【CVE-2026-85148(Use of Hard-coded Credentials)】
Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.

【CVE-2026-85149(Use of Hard-coded Credentials)】
Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.
Solution Update SmartIT Desktop Manager to version 11 or later.
Credit 【CVE-2026-85146】
Huding, Linwz(DEVCORE)

【CVE-2026-85147, CVE-2026-85149】
Jay(DEVCORE)

【CVE-2026-85148】
Huding(DEVCORE)
Public Date 2026-09-04
Top