Jump to the main content block

【Vulnerability Alert】Shiu Chen Information|SmartIT Desktop Manager - Contains Two Critical Cybersecurity Vulnerabilities

publish date : 2026-09-11 update date : 2026-09-11

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026090803095959 Publication Time 2026-09-08 15:28:00
Incident Type ANA-Vulnerability Alert Discovery Time 2026-09-08 15:28:00
Impact Level Low  
[Subject]
【Vulnerability Alert】Shiu Chen Information|SmartIT Desktop Manager - Contains Two Critical Cybersecurity Vulnerabilities
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000006

Shiu Chen Information's SmartIT Desktop Manager contains four security vulnerabilities, including two critical cybersecurity vulnerabilities:

【Shiu Chen Information|SmartIT Desktop Manager - Use of Hard-coded Credentials】(CVE-2026-85146, CVSS: 9.8) An unauthenticated remote attacker may obtain the SSH service account and password of the SmartIT Agent program from the program code.

【Shiu Chen Information|SmartIT Desktop Manager - Use of Hard-coded Credentials】(CVE-2026-85147, CVSS: 7.5) An unauthenticated remote attacker may obtain a specific password from the program code. The password can be used to obtain the AES encryption key used for communications.

【Shiu Chen Information|SmartIT Desktop Manager - Use of Hard-coded Credentials】(CVE-2026-85148, CVSS: 9.8) An unauthenticated remote attacker may use a fixed password to remotely access a user's host.

【Shiu Chen Information|SmartIT Desktop Manager - Use of Hard-coded Credentials】(CVE-2026-85149, CVSS: 5.3) An unauthenticated remote attacker may obtain the SFTP service account and password of the SmartIT Agent program from the program code, thereby browsing the file system of a user's host.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

SmartIT Desktop Manager version 10 and earlier

[Recommended Actions]

Update to SmartIT Desktop Manager version 11 or later

[Reference]

 https://www.twcert.org.tw/tw/cp-132-11176-a4cc2-1.html

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: