由 Lightstar 开发的 SmartIT Desktop Manager 存在“硬编码凭据使用”漏洞。未认证的攻击者可以通过查看 SmartIT Agent 应用程序的源代码,获取其 SFTP 服务的凭据,从而浏览用户主机的文件系统。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Lightstar | SmartIT Desktop Manager | 0 ~ 10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85148 | 9.8 CRITICAL | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
| CVE-2026-85146 | 9.8 CRITICAL | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
| CVE-2026-85147 | 7.5 HIGH | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
No comments yet