CVE-2026-2545Disclosure(ligerosmart / ligerosmart)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketSearch. This manipulation of the argument Profile causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ligerosmart

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-16); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
ligerosmart

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-16: 1Mentions · 2026-02-17: 1PoC Mentioned / Linked · 2026-02-17: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 102-1602-17
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-161
Disclosure1
2026-02-171
General1
Full discourse2 posts
  • NerdieNews@NewsNerdie
    General

    Today's Top Cybersecurity News – February 17, 2026 1. Multiple Stack Buffer Overflow Vulnerabilities in Bosch Infotainment ECU Bluetooth Stack Three distinct stack-based buffer overflow vulnerabilities (CVE-2025-32059, CVE-2025-32061, CVE-2025-32062) have been identified in the Bluetooth stack developed by Alps Alpine for Bosch Infotainment ECUs. These flaws allow remote attackers to execute arbitrary code via malformed packets on the L2CAP channel, posing significant risks to vehicle infotainment system security. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-32062 2. CVE-2026-2553: SQL Injection in tushar-2223 Hotel-Management-System home.php A remote SQL injection vulnerability exists in the HTTP POST handler of the tushar-2223 Hotel-Management-System's home.php file. Manipulating the Name or Email parameters allows attackers to execute arbitrary SQL commands. The exploit is publicly available, increasing the risk of active attacks. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-2553 3. Malicious Chrome Extension Steals 2FA and Analytics from Facebook Business Manager A deceptive Chrome extension posing as a Meta Business Suite productivity tool is actively stealing Two-Factor Authentication (2FA) seeds, one-time codes, and sensitive business analytics from Facebook Business Manager accounts. This exposes users to account takeover risks despite the presence of 2FA protections. Sources: Gbhackers, Therecord https://gbhackers.com/malicious-chrome-extension-exposes-facebook-manager/ 4. Lotus Blossom Hackers Compromise Notepad++ Update Infrastructure for Espionage Between June and December 2025, the state-sponsored Lotus Blossom group breached the official Notepad++ update hosting infrastructure, enabling them to deliver malicious payloads through trusted developer tool updates. This compromise poses significant risks to users by turning a widely used software update channel into an espionage vector. Sources: Cvefeed, Gbhackers https://gbhackers.com/notepad-breached/ 5. Multiple Remote Code Execution and Injection Vulnerabilities Disclosed in Popular Software Several critical and medium severity vulnerabilities have been disclosed affecting multiple software products including LigeroSmart, yued-fe LuLu UI, vichan-devel, Comfast CF-E4, and others. These include remote code execution via command injection, cross-site scripting, and unverified password changes, with some exploits publicly available, increasing the risk of active attacks. Sources: Cvefeed, Gbhackers, Sans https://cvefeed.io/vuln/detail/CVE-2026-2545 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article lists several recently disclosed CVEs with technical details and notes that exploits are publicly available, but it lacks concrete evidence of active exploitation or specific patch information.

    0001055
    54 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2545 Cross-Site Scripting in LigeroSmart AgentTicketSearch via Profile Paramet... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2545 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet announces CVE‑2026‑2545, a cross‑site scripting flaw in LigeroSmart’s AgentTicketSearch, without providing any proof of exploit or mitigation information.

    0000034
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appligerosmartligerosmart---

Explore more