CVE-2026-85149
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Lightstar | SmartIT Desktop Manager | 0 <= 10 | affected |
Weaknesses
- CWE-798: CWE-798 Use of Hard-coded Credentials
References
- https://www.twcert.org.tw/tw/cp-132-11176-a4cc2-1.html
- https://www.twcert.org.tw/en/cp-139-11177-13ca3-2.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.