CVE-2026-85148
—Hard-coded Password in Lightstar SmartIT Desktop Manager Enables Remote Host Access
SmartIT Desktop Manager, a remote-management tool from Lightstar, contains a Use of Hard-coded Credentials flaw (CWE-798) in which a fixed password is built into the software instead of being uniquely generated per installation. Because this fixed password is identical across deployments, any unauthenticated remote attacker who learns it can authenticate to the Desktop Manager service over the network and gain access to the user's host. Successful exploitation yields full remote access to the affected machine, consistent with the high confidentiality, integrity, and availability impact in the critical CVSS 4.0 score of 9.3. Any system running the product whose remote-management service is reachable over the network, especially internet-exposed endpoints used for remote support, is affected. No public proof-of-concept, CISA KEV listing, or confirmed exploitation is known, and EPSS estimates only a ~0.4% probability of exploitation within 30 days.
What to do: Audit endpoints for the presence of SmartIT Desktop Manager, prioritizing hosts whose remote-management service is exposed to the internet, and obtain a patched build from Lightstar when one is released (no fixed version is specified in the available data). Until patching, restrict inbound network access to the Desktop Manager service using firewall or VPN rules, limiting it to trusted management networks. If the product allows it, change the built-in fixed password used for remote connections and monitor for unexplained remote sessions.
| Lightstar SmartIT Desktop Manager | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
- Weakness
- CWE-798
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.