Forwarding Taiwan Computer Emergency Response Team / Coordination Center Cybersecurity Alert TWCERTCC-200-202609-00000006
Sunsea Information product SmartIT Desktop Manager has 4 security vulnerabilities, including 2 critical security vulnerabilities:
【Sunsea Information|SmartIT Desktop Manager - Use of Hard-coded Credentials】(CVE-2026-85146, CVSS: 9.8) Unauthenticated remote attackers can obtain the SSH service account and password for the SmartIT Agent program within the code.
【Sunsea Information|SmartIT Desktop Manager - Use of Hard-coded Credentials】(CVE-2026-85147, CVSS: 7.5) Unauthenticated remote attackers can obtain a specific password within the code, which can be used to acquire the AES encryption key for communication.
【Sunsea Information|SmartIT Desktop Manager - Use of Hard-coded Credentials】(CVE-2026-85148, CVSS: 9.8) Unauthenticated remote attackers can use a fixed password to remotely access user hosts.
【Sunsea Information|SmartIT Desktop Manager - Use of Hard-coded Credentials】(CVE-2026-85149, CVSS: 5.3) Unauthenticated remote attackers can obtain the SFTP service account and password for the SmartIT Agent program within the code, thereby browsing the user host file system.