VYPR

SmartIT Desktop Manager

by Lightstar

CVEs (4)

  • CVE-2026-85148CriSep 4, 2026
    risk 0.64cvss 9.8epss

    SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.

  • CVE-2026-85146CriSep 4, 2026
    risk 0.64cvss 9.8epss

    SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.

  • CVE-2026-85147HigSep 4, 2026
    risk 0.49cvss 7.5epss

    SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.

  • CVE-2026-85149MedSep 4, 2026
    risk 0.34cvss 5.3epss

    SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.