Project Subscriptions
No data.
No advisories yet.
Solution
Update NitroSense to version 5.2.84 or later to fix.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://community.acer.com/en/kb/articles/20052 |
|
Wed, 23 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). This allows the attacker to invoke exposed ddsc RPC functions, including child_process.execSync(), resulting in arbitrary command execution in the application context. | |
| Title | MQTT WebSocket Command Execution Vulnerability in NitroSense | |
| Weaknesses | CWE-306 CWE-78 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Acer
Published:
Updated: 2026-09-23T14:51:10.454Z
Reserved: 2026-06-04T09:22:14.582Z
Link: CVE-2026-50227
Updated: 2026-09-23T14:51:04.020Z
Status : Received
Published: 2026-09-23T08:17:09.383
Modified: 2026-09-23T15:17:14.170
Link: CVE-2026-50227
No data.
OpenCVE Enrichment
Updated: 2026-09-23T14:00:05Z