CVE-2026-50606: Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSense and PredatorSense Software
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Acer System Monitoring (NitroSense)to a version that resolves this vulnerability.Fixed in 5.2.84 - Upgrade
Upgrade
Acer System Monitoring (PredatorSense)to a version that resolves this vulnerability.Fixed in 5.2.109
Event History
Frequently Asked Questions
Who is able to exploit this issue?
The described attack scenario requires a local attacker. The available information does not indicate that it can be exploited remotely.
What could an attacker do with the embedded key?
Under certain circumstances, an attacker may use the hard-coded AES key to access protected information or perform unauthorized actions.
Which software component should be investigated?
The affected component is Acer System Monitoring, which is included with NitroSense and PredatorSense software.