« Volver al listado

Acer

Acer Predator Connect W6X Firmware: vulnerabilidades y CVE

Acer Predator Connect W6X Firmware tiene 5 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses5
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-49199Crítica (10)2.2%—29 may 2026
Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.
CVE-2026-49198Alta (8.3)0.34%—29 may 2026
Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors.
CVE-2026-49197Crítica (10)0.53%—29 may 2026
Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.
CVE-2026-49196Alta (8.6)0.66%—29 may 2026
The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands.
CVE-2026-49195Alta (8.7)0.37%—29 may 2026
Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter3
  2. T1210 Exploitation of Remote Services3
  3. T1190 Exploit Public-Facing Application2
  4. T1005 Data from Local System1
  5. T1078 Valid Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Acer