【Vulnerability Alert】Shiu Chen Information|SmartIT Desktop Manager - Contains Two Critical Cybersecurity Vulnerabilities
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026090803095959 | Publication Time | 2026-09-08 15:28:00 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-08 15:28:00 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Shiu Chen Information|SmartIT Desktop Manager - Contains Two Critical Cybersecurity Vulnerabilities |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000006 Shiu Chen Information's SmartIT Desktop Manager contains four security vulnerabilities, including two critical cybersecurity vulnerabilities: 【Shiu Chen Information|SmartIT Desktop Manager - Use of Hard-coded Credentials】(CVE-2026-85146, CVSS: 9.8) An unauthenticated remote attacker may obtain the SSH service account and password of the SmartIT Agent program from the program code. 【Shiu Chen Information|SmartIT Desktop Manager - Use of Hard-coded Credentials】(CVE-2026-85147, CVSS: 7.5) An unauthenticated remote attacker may obtain a specific password from the program code. The password can be used to obtain the AES encryption key used for communications. 【Shiu Chen Information|SmartIT Desktop Manager - Use of Hard-coded Credentials】(CVE-2026-85148, CVSS: 9.8) An unauthenticated remote attacker may use a fixed password to remotely access a user's host. 【Shiu Chen Information|SmartIT Desktop Manager - Use of Hard-coded Credentials】(CVE-2026-85149, CVSS: 5.3) An unauthenticated remote attacker may obtain the SFTP service account and password of the SmartIT Agent program from the program code, thereby browsing the file system of a user's host. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
SmartIT Desktop Manager version 10 and earlier |
|||
|
[Recommended Actions] Update to SmartIT Desktop Manager version 11 or later |
|||
|
[Reference] |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





