PT-2026-97205 · Acer · Nitrosense
CVSS v4.0
6.1
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Acer NitroSense versions prior to 5.2.63
Description
An unauthenticated local attacker can connect to the MQTT broker via the localhost WebSocket endpoint. This access allows the invocation of exposed ddsc RPC functions, specifically the
child process.execSync() function, which enables arbitrary command execution within the application context.Recommendations
Update Acer NitroSense to a version later than 5.2.62.
Fix
OS Command Injection
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nitrosense