ZeroHour

CVE-2026-85147

Hard-coded Credentials in Lightstar SmartIT Desktop Manager Expose Encryption Keys

CVSS 4.0
8.7 high
EPSS
<1%p10
Published
()
Modified
AI analysis

Lightstar's SmartIT Desktop Manager contains a hard-coded credential: a specific password embedded in the product's source code (CWE-284). An unauthenticated remote attacker who recovers this password from the source code can use it to retrieve the AES encryption key that protects the product's communications. The impact is confidentiality-focused — per the CVSS 4.0 vector, an attacker can decrypt communication traffic (VC:H) but gains no integrity or availability impact. Any deployment of SmartIT Desktop Manager is affected, though the available data does not specify affected version ranges. There is currently no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Check whether SmartIT Desktop Manager is deployed in your environment and whether its service is exposed to the internet or untrusted networks; restrict access to trusted management networks until a fix is available. Monitor the vendor (and TWCERT/CC, which assigned this CVE) for a patched release or advisory, since no fixed version is specified in the available data. After patching, consider re-establishing encrypted sessions, since the hard-coded credential and derived AES key may have been used to decrypt recorded traffic.

Affected
Lightstar SmartIT Desktop Manager
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.

Weakness
CWE-284
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.