Description
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the service to unintended network access.
Published: 2026-09-17
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Network Access
Action: Restrict Listening
AI Analysis

Impact

A WebSocket service in the Acer System Monitoring component of NitroSense and PredatorSense was configured to listen on all network interfaces. This configuration may expose the service to unintended network access, potentially allowing unauthenticated remote participants to connect to the service.

Affected Systems

The vulnerability applies to the Acer System Monitoring component included with NitroSense and PredatorSense software. No specific version information is stated, so all current installations may be affected until a vendor update is released.

Risk and Exploitability

The CVSS score of 2.7 indicates a low severity impact, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local network access, requiring an attacker to be on the same network segment to reach the listening service.

Generated by OpenCVE AI on September 18, 2026 at 00:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and install the latest Acer System Monitoring firmware that limits WebSocket binding to the loopback interface or a specific internal interface; consult the Acer community or vendor advisories for a patch.
  • If a firmware update is not yet available, configure the system firewall or network ACLs to block external inbound traffic to the WebSocket port from all but trusted internal sources.
  • If the WebSocket service is not required for monitoring, disable the service entirely to eliminate the exposure.

Generated by OpenCVE AI on September 18, 2026 at 00:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Acer
Acer system Monitoring
Vendors & Products Acer
Acer system Monitoring

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the service to unintended network access.
Title WebSocket Exposure Vulnerability in NitroSense and PredatorSense Software
Weaknesses CWE-668
References
Metrics cvssV4_0

{'score': 2.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U'}


Subscriptions

Acer System Monitoring
cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-09-17T12:26:18.604Z

Reserved: 2026-06-05T07:22:32.054Z

Link: CVE-2026-50607

cve-icon Vulnrichment

Updated: 2026-09-17T12:26:12.518Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T08:17:01.320

Modified: 2026-09-18T16:25:08.493

Link: CVE-2026-50607

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:51Z

Weaknesses
  • CWE-668

    Exposure of Resource to Wrong Sphere