acer
35 known vulnerabilities affecting acer products.
Products
connect_m6e_5g 26
connect_m6e_5g_firmware 26
predator_connect_w6x 5
predator_connect_w6x_firmware 5
wave_7 2
wave_7_firmware 2
care_center 1
predatorsense 1
nitrosense 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-49199 | Medium | 1.3% | 9.8 | Crafted MQTT messages can trigger command injection, resulting in root-level cod… | |
| CVE-2026-49200 | Medium | 0.5% | 9.8 | The acer_cgi.log file in the device firmware is accessible without authenticatio… | |
| CVE-2026-49190 | Medium | 0.4% | 8.8 | The system fails to evaluate instructional permissions over multiple internal op… | |
| CVE-2026-49185 | Medium | 0.4% | 9.8 | The FieldX MDM adb messaging topic passes unverified payloads directly into Runt… | |
| CVE-2026-49196 | Medium | 0.4% | 7.2 | The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing … | |
| CVE-2026-49197 | Medium | 0.3% | 9.8 | Web endpoints intended for the Acer Connect app improperly validate the HTTP Aut… | |
| CVE-2026-49186 | Medium | 0.3% | 9.8 | The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). … | |
| CVE-2026-49188 | Medium | 0.3% | 9.8 | The ai_cmd utility executes with full root permissions. It pipes socket inputs d… | |
| CVE-2026-49191 | Medium | 0.3% | 9.8 | The production build of the M3WebServer hard-codes its backend API keys, which c… | |
| CVE-2026-50211 | Medium | 0.3% | 9.8 | Leftover engineering diagnostics and factory-level diagnostic software remain ex… | |
| CVE-2026-49201 | Medium | 0.3% | 9.8 | The upload.cgi binary, responsible for processing device backups, contains a har… | |
| CVE-2026-49202 | Medium | 0.3% | 8.6 | Internal multimedia session archives are accessible without authentication, exac… | |
| CVE-2026-49187 | Medium | 0.2% | 7.5 | The hard-coded APK resource files never expire, and the shared scepter leads to … | |
| CVE-2026-49193 | Medium | 0.2% | 7.5 | Overly permissive configuration settings on cloud storage containers expose acti… | |
| CVE-2026-50210 | Medium | 0.2% | 7.5 | The device encrypts data using AES-CBC with static zero-filled Initialization Ve… | |
| CVE-2026-50225 | Medium | 0.2% | 9.1 | The registration path /v1/account/register provides no bot mitigation mechanisms… | |
| CVE-2026-50205 | Medium | 0.2% | 8.2 | System log files output unencrypted SMTP server authentication passwords alongsi… | |
| CVE-2026-49194 | Medium | 0.2% | 8.8 | The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standa… | |
| CVE-2026-50213 | Medium | 0.2% | 7.5 | The account validation endpoint /v1/User/validate returns comprehensive user pro… | |
| CVE-2026-49195 | Medium | 0.2% | 8.8 | Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9… | |
| CVE-2026-49203 | Medium | 0.2% | 8.3 | Crucial management API endpoints for cellular eSIM allocation do not validate ca… | |
| CVE-2026-50214 | Medium | 0.2% | 9.8 | The /v1/Plan service relies entirely on a shared global API token for full admin… | |
| CVE-2026-50208 | Medium | 0.1% | 9.4 | High-risk TrustAllCerts routines disable standard TLS certificate validation. Co… | |
| CVE-2026-50207 | Medium | 0.1% | 7.8 | The system Binder boundary accepts unverified pass-through AT commands, giving l… | |
| CVE-2026-8069 | Medium | 0.1% | 7.8 | PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation … | |
| CVE-2026-49189 | Medium | 0.1% | 7.8 | Unchecked public access permissions on a core Broadcast Receiver allow unauthori… | |
| CVE-2026-50209 | Medium | 0.1% | 7.8 | Broadcast events allow malicious software to rewrite the device's default Mobile… | |
| CVE-2026-50206 | Low | 0.7% | 6.8 | Incoming VPN network profile settings fail to process special characters safely,… | |
| CVE-2026-50224 | Low | 0.2% | 4.9 | The web administration panel binds broadly to the public IPv6 address space on p… | |
| CVE-2026-49198 | Low | 0.2% | 4.9 | Improper access control in the MQTT broker allows wildcard topic subscriptions, … | |
| CVE-2026-50226 | Low | 0.2% | 5.3 | Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forg… | |
| CVE-2026-9490 | Low | 0.2% | 5.5 | A security vulnerability has been identified in Acer Care Center where the ACCSv… | |
| CVE-2026-50212 | Low | 0.2% | 6.5 | Weak validation logic within device dissociation API routines allows a remote en… | |
| CVE-2026-49204 | Low | 0.2% | 6.5 | Leftover debug modules contain fixed credentials for internal AWS Cognito test s… | |
| CVE-2026-49192 | Low | 0.1% | 5.4 | The summary service endpoint suffers from an IDOR vulnerability where it fails t… |