由 Lightstar 开发的 SmartIT Desktop Manager 存在“硬编码凭据”漏洞。未认证的远程攻击者可以直接从应用程序源代码中获取 SSH 服务账户的凭证和密码,从而获取对 SmartIT 代理(SmartIT Agent)的访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Lightstar | SmartIT Desktop Manager | 0 ~ 10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85148 | 9.8 CRITICAL | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
| CVE-2026-85147 | 7.5 HIGH | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
| CVE-2026-85149 | 5.3 MEDIUM | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
No comments yet