在 NitroSense 和 PredatorSense 附带的 Acer Agent Service 组件中发现了一个漏洞。该漏洞由软件中硬编码的 AES 加密密钥引起。在特定情况下,本地攻击者可能利用该嵌入密钥访问受保护的信息或执行未经授权的操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Acer | Agent Service | * ~ 1.2.110.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50605 | 7.4 HIGH | Privilege Escalation Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50609 | 7.4 HIGH | Unauthorized Registry Modification Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50610 | 7.4 HIGH | Improper Access control Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50604 | 4.9 MEDIUM | Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50607 | 2.7 LOW | WebSocket Exposure Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50606 | 1.2 LOW | Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSense and Preda |
| CVE-2026-50608 | 1.2 LOW | Authentication Vulnerability in NitroSense and PredatorSense Software |
No comments yet