在随 NitroSense 和 PredatorSense 附带的 Acer 系统监控组件中,发现了一个安全漏洞。WebSocket 握手过程未能在允许与服务建立连接之前强制进行身份验证。在特定情况下,未经授权的访问者可能得以使用该服务功能。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Acer | System Monitoring | * ~ 1.0.19.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50605 | 7.4 HIGH | Privilege Escalation Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50609 | 7.4 HIGH | Unauthorized Registry Modification Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50610 | 7.4 HIGH | Improper Access control Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50603 | 4.9 MEDIUM | Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense and PredatorS |
| CVE-2026-50604 | 4.9 MEDIUM | Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50607 | 2.7 LOW | WebSocket Exposure Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50606 | 1.2 LOW | Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSense and Preda |
No comments yet