CVE-2026-50227
MQTT WebSocket Command Execution Vulnerability in NitroSense
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). This allows the attacker to invoke exposed ddsc RPC functions, including child_process.execSync(), resulting in arbitrary command execution in the application context.
| CWE | CWE-306 CWE-78 |
| Vendor | acer |
| Product | nitrosense v5 |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for acer nitrosense v5
Be the first to know when new unknown vulnerabilities affecting acer nitrosense v5 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Acer / NitroSense V5
* โค 5.2.62
References
Credits
๐ Ayush Choudhary