CVE-2026-85147 Details
Description
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.
A vulnerability allowing the use of hard-coded credentials has been identified in Lightstar's SmartIT Desktop Manager, affecting version 10 and earlier. This vulnerability allows unauthenticated remote attackers to extract specific passwords from the application's source code. These passwords can be used to access the AES encryption key for communication, retrieve SSH service account credentials, or gain remote access to user hosts via fixed passwords. Additionally, SFTP service credentials can be obtained, enabling attackers to browse the file system of the user's host.
Users are advised to update SmartIT Desktop Manager to version 11 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-11177-13ca3-2.html | [email protected] | AdvisoryBundleRemedy |
| https://www.twcert.org.tw/tw/cp-132-11176-a4cc2-1.html | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Lightstar SmartIT Desktop Manager | <= 10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion