由 Lightstar 开发的 SmartIT Desktop Manager 存在硬编码凭据使用漏洞。未经认证的远程攻击者可以从源代码中获取一个特定的密码,该密码可用于获取用于通信的 AES 加密密钥。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Lightstar | SmartIT Desktop Manager | 0 ~ 10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85148 | 9.8 CRITICAL | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
| CVE-2026-85146 | 9.8 CRITICAL | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
| CVE-2026-85149 | 5.3 MEDIUM | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
No comments yet