Executive brief
Acer's NitroSense and PredatorSense monitoring software include a system monitoring component with a WebSocket service that listens on all network interfaces. This misconfiguration may allow unintended network access to the service, potentially exposing system information to unauthorized users on the network.
Technical details
A WebSocket service in Acer's System Monitoring component was misconfigured to listen on all network interfaces (0.0.0.0) rather than being restricted to localhost or specific interfaces. This configuration flaw allows remote or local network users to access the service without authentication or appropriate network segmentation. The vulnerability affects both NitroSense and PredatorSense products that bundle this monitoring component. Patch availability and specific impact details are not yet confirmed in accessible documentation.
Affected products
- Acer NitroSense <UNKNOWN>
- Acer PredatorSense <UNKNOWN>
Timeline
- 2026-09-17: disclosed: CVE-2026-50607 published on NVD