已在随 NitroSense 和 PredatorSense 一起提供的 Acer Agent Service 组件中识别到一个漏洞。该组件在套接字握手过程中未适当要求身份验证,即授予服务访问权限。在某些情况下,可能会建立未授权连接,从而可能允许访问本应受限的功能。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Acer | Agent Service | * ~ 1.2.110.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50605 | 7.4 HIGH | Privilege Escalation Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50609 | 7.4 HIGH | Unauthorized Registry Modification Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50610 | 7.4 HIGH | Improper Access control Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50603 | 4.9 MEDIUM | Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense and PredatorS |
| CVE-2026-50607 | 2.7 LOW | WebSocket Exposure Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50606 | 1.2 LOW | Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSense and Preda |
| CVE-2026-50608 | 1.2 LOW | Authentication Vulnerability in NitroSense and PredatorSense Software |
No comments yet