Acer
Acer Connect M6E 5G Firmware: vulnerabilidades y CVE
Acer Connect M6E 5G Firmware tiene 26 vulnerabilidades publicadas, 26 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses26
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-50226 | Media (6.9) | 0.31% | — | 4 jun 2026 | Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected… |
| CVE-2026-50225 | Alta (8.8) | 0.44% | — | 4 jun 2026 | The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database. |
| CVE-2026-50224 | Media (6.9) | 0.40% | — | 4 jun 2026 | The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN. |
| CVE-2026-50214 | Crítica (9.3) | 0.25% | — | 4 jun 2026 | The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans. |
| CVE-2026-50213 | Alta (8.7) | 0.39% | — | 4 jun 2026 | The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings. |
| CVE-2026-50212 | Alta (7.1) | 0.27% | — | 4 jun 2026 | Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service. |
| CVE-2026-50211 | Alta (8.8) | 0.52% | — | 4 jun 2026 | Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers. |
| CVE-2026-50210 | Media (6.9) | 0.42% | — | 4 jun 2026 | The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption. |
| CVE-2026-50209 | Crítica (9.3) | 0.14% | — | 4 jun 2026 | Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker. |
| CVE-2026-50208 | Crítica (9.2) | 0.24% | — | 4 jun 2026 | High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic. |
| CVE-2026-50207 | Alta (8.5) | 0.18% | — | 4 jun 2026 | The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity. |
| CVE-2026-50206 | Alta (8.5) | 1.6% | — | 4 jun 2026 | Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files. |
| CVE-2026-50205 | Alta (8.8) | 0.41% | — | 4 jun 2026 | System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data. |
| CVE-2026-49204 | Media (6.9) | 0.27% | — | 4 jun 2026 | Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation. |
| CVE-2026-49203 | Alta (7.2) | 0.28% | — | 4 jun 2026 | Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted. |
| CVE-2026-49202 | Alta (8.8) | 0.45% | — | 4 jun 2026 | Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft. |
| CVE-2026-49194 | Crítica (9.4) | 0.42% | — | 4 jun 2026 | The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface. |
| CVE-2026-49193 | Alta (8.7) | 0.42% | — | 4 jun 2026 | Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet. |
| CVE-2026-49192 | Media (5.3) | 0.23% | — | 4 jun 2026 | The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping. |
| CVE-2026-49191 | Crítica (9.3) | 0.53% | — | 4 jun 2026 | The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages. |
| CVE-2026-49190 | Crítica (9.4) | 0.81% | — | 4 jun 2026 | The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions. |
| CVE-2026-49189 | Alta (8.5) | 0.14% | — | 4 jun 2026 | Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations. |
| CVE-2026-49188 | Alta (8.7) | 0.63% | — | 4 jun 2026 | The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands. |
| CVE-2026-49187 | Alta (8.7) | 0.42% | — | 4 jun 2026 | The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse. |
| CVE-2026-49186 | Alta (8.6) | 0.47% | — | 4 jun 2026 | The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control… |
| CVE-2026-49185 | Crítica (10) | 0.56% | — | 4 jun 2026 | The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.